Back to skill

Security audit

Cclaw

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its comedy writing, video editing, and poster purpose, but it includes under-scoped local command execution and hard-coded personal file reads/writes that users should review before installing.

Review this skill before installing. It appears aimed at comedy creation and media production, not credential theft or exfiltration, but you should run FFmpeg actions only after inspecting the exact command and output path, avoid overwriting originals, and do not run the bundled poster_output scripts unless you replace the hard-coded personal paths with files and destinations you explicitly choose.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
poster_output/generate_poster.py:31
Finding

Hard-Coded Personal File Access and Unprotected Fixed-Path Output

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (124)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broad multi-function comedy tool covering script generation, FFmpeg video editing, and poster generation aligned to several platform specs. The supplied code chunk is much narrower: it is a standalone PIL script that creates one poster layout, optionally loads a local profile photo from a specific Windows desktop path, uses Windows fonts, and saves the result to a specific local workspace path. This is materially different from the broader declared behavior for this chunk, especially because it accesses local files through undeclared absolute paths and lacks the described script-generation, video-editing, and platform-spec functionality. Poster generation itself is related to the description, but the implementation and resource access are more specific and inconsistent with the declared capabilities, so this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description claims a multi-capability comedy AI tool covering script writing, video editing, and poster generation with platform-specific support. The actual code chunk is much narrower: it is a standalone poster renderer for one specific poster. It contains fixed content ('DIEGO', specific Chinese title and hook text), relies on hardcoded local Windows file paths for an input photo and output PNG, and does not implement video editing, comedy generation, or marketplace specification support. While poster generation is part of the declared purpose, the supplied code does not accurately represent the broader declared functionality and includes concrete local file access behavior that is not described.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description claims a broad multi-capability skill covering comedy content generation, video editing, and poster generation. The actual code chunk only performs one narrow function: creating a specific poster image with fixed text, styling, and optional local photo compositing. It does not implement script generation, AI behavior, video editing, FFmpeg integration, or ticketing-platform specification support. While poster generation is part of the declared description, the actual code is materially narrower and includes hardcoded local file access behavior. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · cclaw/knowledge/cases/manzai/README.md (reported line 1)May include surrounding context.

md
# 剧本输出模板

> 适用:60-120分钟完整喜剧剧本。核心是人物弧线 + 完整结构 + 性格喜剧。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · cclaw/knowledge/cases/parody/README.md (reported line 1)May include surrounding context.

md
# 剧本输出模板

> 适用:60-120分钟完整喜剧剧本。核心是人物弧线 + 完整结构 + 性格喜剧。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · cclaw/knowledge/cases/script/README.md (reported line 1)May include surrounding context.

md
# 剧本输出模板

> 适用:60-120分钟完整喜剧剧本。核心是人物弧线 + 完整结构 + 性格喜剧。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · cclaw/knowledge/cases/sketch/README.md (reported line 1)May include surrounding context.

md
# 剧本输出模板

> 适用:60-120分钟完整喜剧剧本。核心是人物弧线 + 完整结构 + 性格喜剧。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · knowledge/cases/manzai/README.md (reported line 1)May include surrounding context.

md
# 剧本输出模板

> 适用:60-120分钟完整喜剧剧本。核心是人物弧线 + 完整结构 + 性格喜剧。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · knowledge/cases/parody/README.md (reported line 1)May include surrounding context.

md
# 剧本输出模板

> 适用:60-120分钟完整喜剧剧本。核心是人物弧线 + 完整结构 + 性格喜剧。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · knowledge/cases/script/README.md (reported line 1)May include surrounding context.

md
# 剧本输出模板

> 适用:60-120分钟完整喜剧剧本。核心是人物弧线 + 完整结构 + 性格喜剧。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · knowledge/cases/sketch/README.md (reported line 1)May include surrounding context.

md
# 剧本输出模板

> 适用:60-120分钟完整喜剧剧本。核心是人物弧线 + 完整结构 + 性格喜剧。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · modules/writing/absurdist-template.md (reported line 1)May include surrounding context.

md
# 剧本输出模板

> 适用:60-120分钟完整喜剧剧本。核心是人物弧线 + 完整结构 + 性格喜剧。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · modules/writing/parody-template.md (reported line 1)May include surrounding context.

md
# 剧本输出模板

> 适用:60-120分钟完整喜剧剧本。核心是人物弧线 + 完整结构 + 性格喜剧。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · modules/writing/satire-template.md (reported line 1)May include surrounding context.

md
# 剧本输出模板

> 适用:60-120分钟完整喜剧剧本。核心是人物弧线 + 完整结构 + 性格喜剧。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · modules/writing/script-template.md (reported line 1)May include surrounding context.

md
# 剧本输出模板

> 适用:60-120分钟完整喜剧剧本。核心是人物弧线 + 完整结构 + 性格喜剧。

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 4)May include surrounding context.

md
---
name: cclaw
version: 1.10.0
description: "Open-source comedy AI + video editing + poster generation. Create standup/sketch/manzai/scripts, edit videos via FFmpeg, and generate comedy posters via canvas-design. Supports Damai/Maoyan/Xiudong platform specs. Keywords: comedy, standup, sketch, video, edit, poster, canvas."
description_zh: "全球首个开源喜剧 AI + 视频剪辑 + 海报生成工具。创作脱口秀/小品/漫才/剧本等喜剧内容,或通过自然语言脚本驱动 FFmpeg 进行视频剪辑,或生成脱口秀/演出/金句海报及大麦/猫眼/秀动等平台标准规格物料。"
category: "data-analysis"
---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs the agent to generate and execute FFmpeg commands from natural-language input, but does not include a clear warning, constraint model, or safety boundary for command execution. In skill ecosystems, natural-language-to-shell or tool execution can become dangerous if user-controlled parameters are translated into arbitrary command arguments, file paths, network inputs, or overwrite operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language content of the skill documentation is effectively constrained to Chinese, and there is no indication that users may choose another language or that the skill is intended only for a Chinese-speaking or region-specific audience. Per the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly states it will generate FFmpeg commands and execute them, but it does not disclose that this may invoke local command-line tooling and modify or overwrite user media files. In a skill that transforms natural-language requests into executable media-processing commands, missing consent and safety boundaries increases the chance of unintended file modification, destructive edits, or risky command construction being triggered by ambiguous prompts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The entire command reference is written in Chinese and includes hard requirements such as output constraints under '创作时必须', but it does not indicate that language is configurable or user-selectable. This can amount to a language policy violation if the skill forces a specific language or locale without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The video commands encourage FFmpeg-driven editing, concatenation, subtitling, and transcoding on user-supplied file paths without warning about destructive writes, output locations, or overwrite behavior. In a tool-integrated agent, this can lead to accidental data loss or unintended modification of local files, especially if the implementation defaults to in-place replacement or reuses filenames.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.