Back to skill

Security audit

ZeeLin-video-analysis 视频拉片

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent video-analysis purpose, but it uploads private videos and an App-Key to a hard-coded plain-HTTP service, creating a serious review concern.

Review this carefully before installing. Only use it for videos you are willing to send to the Zeelin service, do not place valuable long-lived credentials in the template config, and avoid using the skill until the provider supports HTTPS and gives clear upload, retention, and credential-handling assurances.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
templates/config.json:4
Finding

Plaintext Transmission and Insecure Storage of API Credentials and Private Video Data

Content
View full analysis

Vulnerability Details

File Locations:

  • templates/config.json:4-5
  • SKILL.md:58-61
  • SKILL.md:91-101
  • SKILL.md:143-160
  • SKILL.md:203

Vulnerability Type: Unencrypted transmission of sensitive data and insecure credential storage
Risk Level: High

Vulnerable Code

The active configuration directs requests to an unencrypted HTTP endpoint and instructs users to place their App-Key directly in a project file:

json
"service_url": "http://47.98.180.113:8083",
"Zeelin_App_Key": "Your real AppKey",

The documented upload request sends both the App-Key and the complete local video through that HTTP endpoint:

bash
curl -X POST "http://47.98.180.113:8083/api/skill/upload" \
  -F "appKey=YOUR_APP_KEY" \
  -F "file=@/path/to/local/video.mp4"

The analysis request also transmits the App-Key without transport encryption:

bash
curl -X POST "http://47.98.180.113:8083/api/skill/video" \
  -H "Content-Type: application/json" \
  -d '{
    "appKey": "YOUR_APP_KEY",
    "videos": [
      {"sequence": 1, "oss": "https://jumuai.oss-cn-hangzhou.aliyuncs.com/...video1.mp4"},
      {"sequence": 2, "oss": "https://jumuai.oss-cn-hangzhou.aliyuncs.com/...video2.mp4"}
    ]
  }'

Task status and resulting analysis data are likewise retrieved over HTTP:

bash
curl "http://47.98.180.113:8083/api/skill/status/analysis_xxx"

Technical Analysis

HTTP provides neither transport confidentiality nor server authentication. Any attacker able to observe or modify traffic between the agent and the configured service can read multipart uploads, JSON request bodies, task identifiers, status responses, and analysis results.

Because the App-Key is placed in form data or a JSON body, it is exposed directly in plaintext while crossing the network. The video file is also uploaded before any HTTPS OSS URL is returned, so the later use of an HTTPS object-storage URL does ...[truncated 2582 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace every HTTP API endpoint with an authenticated HTTPS endpoint under the documented service domain.
  2. Remove the bare-IP service URL and use a stable domain with a certificate issued by a trusted certificate authority.
  3. Reject HTTP redirects, TLS certificate errors, hostname mismatches, expired certificates, and attempts to downgrade from HTTPS to HTTP.
  4. Update all upload, submission, polling, and result-retrieval examples to use HTTPS consistently.
  5. Store the App-Key in a platform secret store, environment variable, or operating-system credential manager rather than templates/config.json.
  6. Keep only a clearly named placeholder in the distributed configuration and add real credential files to .gitignore or an equivalent exclusion mechanism.
  7. Rotate any App-Key that has previously been transmitted over HTTP or committed to a repository.
  8. Prefer an authorization header over form or JSON fields if the service supports it, while recognizing that HTTPS remains mandatory regardless of credential placement.
  9. Require explicit user confirmation before uploading a local video, clearly identifying the external service, destination, and data being transferred.
  10. Apply short-lived, narrowly scoped credentials and service-side quotas to limit the impact of credential theft.
  11. Avoid logging request bodies, multipart form fields, authorization data, object URLs containing signatures, or raw analysis responses containing sensitive information.
  12. Consider certificate pinning or equivalent endpoint verification where the deployment model and certificate-rotation process can support it safely.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs uploading local video files and an appKey to a remote service but does not provide a clear privacy or security warning beforehand. Because videos may contain sensitive personal, confidential, or copyrighted material, and the service endpoint is third-party infrastructure, lack of informed consent significantly increases the risk of unintended data disclosure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is triggered by broad phrases like '分析视频' and '视频处理', which can cause accidental activation when a user is merely discussing video analysis rather than consenting to upload a local file. In this skill’s context, activation can lead to transmission of local video content and credentials to a remote third-party service, making ambiguity materially risky.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

The skill sends an appKey and video analysis request data to a hard-coded external endpoint using plain HTTP rather than HTTPS. This exposes credentials and potentially sensitive metadata to interception or tampering in transit, and the surrounding skill flow also uploads local video content to the same remote service, amplifying the confidentiality risk.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

示例请求:

bash
curl -X POST "http://47.98.180.113:8083/api/skill/video" \
  -H "Content-Type: application/json" \
  -d '{
    "appKey": "YOUR_APP_KEY",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill mandates generating a local Markdown file for results without warning the user that a file will be created on disk. This can surprise users, leave sensitive analysis artifacts locally, and increase exposure if the markdown contains personal or confidential content extracted from the uploaded video.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The metadata name and description are written entirely in Chinese without any indication that language selection follows user preference or system locale. This can steer invocation or outputs toward Chinese unexpectedly, creating confusion, incorrect routing, or poor user experience for users expecting another language.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description states broad capabilities like analyzing video content, extracting entities, generating relationship graphs, and character profiles, but does not clearly limit invocation conditions or scope. This can cause the agent to trigger the skill in overly broad contexts involving uploaded videos, increasing the chance of unintended data processing or misuse on sensitive media.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill name and description are presented only in Chinese, with no indication that users can choose another language or locale. This can violate a language/locale policy when the skill effectively constrains interaction to a single language without explicit opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill claims to support local video upload analysis, but the configuration points to a remote service over plain HTTP. This creates a data exfiltration and privacy risk because uploaded videos and derived metadata may be transmitted off-device without clear disclosure, and HTTP adds interception/tampering risk in transit.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Use of an external network endpoint is not adequately justified by the stated purpose of local video analysis. In this context, users may reasonably expect files to remain local, so sending them to a remote server can violate user expectations, privacy requirements, and data handling policies.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
templates/config.json:4