Back to skill

Security audit

MiniMax

Security checks for vulnerabilities and agentic risk

Overview

This MiniMax skill is a disclosed API workflow helper with local notes and remote generation calls that are scoped to the user's MiniMax tasks.

Install this only if you are comfortable sending prompts, approved media, and generation parameters to MiniMax services. Define activation and persistence preferences during setup, avoid storing full prompts or assets in ~/minimax/, and require explicit approval before private media uploads, voice imitation, paid long-running jobs, or remote MCP hosts.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · memory-template.md (reported line 15)May include surrounding context.

md
integration: pending | done | declined

## Context
<!-- What the user is building with MiniMax and why -->
<!-- Example: Text plus speech workflow for narrated product demos with strict approval before media upload -->

## Activation Boundaries

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 145)May include surrounding context.

md
- any rejected or unused assets that never get uploaded

This skill does NOT:
- treat compatible SDKs as exact feature matches without verification
- upload private media, voice references, or lyrics without explicit user intent
- enable remote MCP or broad tool access without explicit approval
- claim that every MiniMax modality is synchronous or instantly available

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · media-generation.md (reported line 41)May include surrounding context.

md
- confirm rights for images, music references, lyrics, logos, and character likenesses before upload
- treat long-running generation as paid remote compute and keep the user informed
- avoid hidden rerun loops that can burn credits without consent

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instruction says to use the file when the user says "which MiniMax model?" or when the workflow is "drifting," but the second condition is subjective and the quoted phrase could arise in general discussion rather than an explicit skill invocation. The file does not provide exclusion conditions or tighter scope to distinguish intended routing use from incidental mentions.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 164)May include surrounding context.

md
## Common Mistakes

- Choosing a compatible interface first and only later picking the model.
- Using quality-first models in latency-critical loops without checking response budget.
- Treating video and music as if they will return like text.
- Forgetting that live model menus can change, which breaks stale pinned lists.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · model-routing.md (reported line 59)May include surrounding context.

md
## Common Mistakes

- Choosing a compatible interface first and only later picking the model.
- Using quality-first models in latency-critical loops without checking response budget.
- Treating video and music as if they will return like text.
- Forgetting that live model menus can change, which breaks stale pinned lists.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The activation guidance is overly broad, covering many related terms and use cases such as MiniMax, Hailuo, compatible SDKs, speech generation, and MCP-backed work. This can cause the skill to activate outside the user's intent, increasing the chance that it injects instructions or captures workflow context in unrelated conversations, especially because it is designed to act proactively.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.