Back to skill

Security audit

缪斯视频创作skill

Security checks for vulnerabilities and agentic risk

Overview

This video-planning skill is not clearly harmful, but it understates optional AI-generation behavior and has unsafe export handling for untrusted project content.

Review before installing. Use it as a planning/export skill only if you are comfortable with optional handoff to image/video generation tools, and avoid opening or sharing generated HTML/XLSX exports from untrusted briefs until the exporter escapes HTML and neutralizes spreadsheet formulas. No evidence was found of persistence, credential theft, or destructive behavior.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/export_html.py:23
Finding

Stored HTML and JavaScript Injection in Generated HTML Exports

Content
View full analysis
str: if val is None: return default s = str(val).strip() return s if s else default ``` Project-level values are collected without escaping: ```python simple = { "project.title": safe_str(project.get("title")), "project.scene_type": safe_str(project.get("scene_type")), "project.duration_est": safe_str(project.get("duration_est")), "project.aspect_ratio": safe_str(project.get("aspect_ratio"), "16:9"), "project.genre": safe_str(project.get("genre")), "project.platform": safe_str(project.get("platform")), "project.language": safe_str(project.get("language"), "zh-CN"), "director_notes.vision": safe_str(director_notes.get("vision")), "script.logline": safe_str(script.get("logline")), "script.structure": safe_str(script.get("structure")), "script._meta.writer_revision": safe_str(resolve_path(script, "_meta.writer_revision", "1")), "script._meta.dp_revision": safe_str(resolve_path(script, "_meta.dp_revision", "1")), "script._meta.director_approved": safe_str(resolve_path(script, "_meta.director_approved", "false")), "_version": VERSION, "_generated_at": datetime.now(timezone.utc).strftime("%Y-%m-%dT%H:%M:%SZ"), "_panels_count": str(len(storyboard)), "_grid_layout": "2×3" if len(storyboard) <= 6 else "3×3", "_is_3x3": "true" if len(storyboard) > 6 else "", } de ...[truncated 4072 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/export_xlsx.py:112
Finding

Spreadsheet Formula Injection in Excel Export

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (122)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The manifest explicitly says the skill is not for AI image/video generation, yet the documented downstream behavior includes producing prompts or configurations for ComfyUI, Kling, Runway, and similar systems. That inconsistency is dangerous because policy, review, or user consent decisions may rely on the declared non-generation scope, while the actual outputs can directly facilitate automated media generation workflows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest explicitly says the skill is not for AI image/video generation, yet the documented downstream behavior includes producing prompts or configurations for ComfyUI, Kling, Runway, and similar systems. That inconsistency is dangerous because policy, review, or user consent decisions may rely on the declared non-generation scope, while the actual outputs can directly facilitate automated media generation workflows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The manifest explicitly says the skill is not for AI image/video generation, yet the documented downstream behavior includes producing prompts or configurations for ComfyUI, Kling, Runway, and similar systems. That inconsistency is dangerous because policy, review, or user consent decisions may rely on the declared non-generation scope, while the actual outputs can directly facilitate automated media generation workflows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The manifest explicitly says the skill is not for AI image/video generation, yet the documented downstream behavior includes producing prompts or configurations for ComfyUI, Kling, Runway, and similar systems. That inconsistency is dangerous because policy, review, or user consent decisions may rely on the declared non-generation scope, while the actual outputs can directly facilitate automated media generation workflows.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill metadata explicitly says it is not for AI image/video generation, yet this reference document contains operational instructions telling the agent to call an image generation tool. That creates a scope-violation path where the agent can execute functionality outside the declared contract, increasing the chance of unauthorized tool use and user expectation mismatch.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

Embedding explicit image-generation execution steps in a video-planning skill introduces a capability not justified by the skill's stated purpose. In context, this is more dangerous because the skill is supposed to help with planning, scripting, and storyboarding—not invoke generative media tools—so the hidden expansion could bypass product boundaries or governance controls.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The storyboard phase goes beyond planning by generating image_prompt values and optionally calling image_gen to create reference images, directly conflicting with the skill's stated non-generation scope. Because this occurs late in the pipeline and is tied to full project state, it can trigger unanticipated external processing of detailed user content and materially expand the skill's operational surface.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/prompt_assembler.py (reported line 315)May include surrounding context.

python
f"Cinematic quality, 4K, smooth motion."
        )
        prompts.append(prompt)
    return prompts


def build_runway_prompts(project_state: dict) -> list:

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/prompt_assembler.py (reported line 328)May include surrounding context.

python
f"Cinematic quality, 4K, smooth motion."
        )
        prompts.append(prompt)
    return prompts


def build_runway_prompts(project_state: dict) -> list:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README advertises very broad trigger phrases such as '帮我策划'/'帮我构思'/'设计'/'写脚本'/'画分镜', which overlap with many ordinary creative requests. In an agent environment that auto-routes by natural language, this can cause accidental invocation, prompt capture, or inappropriate takeover of requests that should be handled by a different skill, increasing the chance of misrouting and unintended instruction injection.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documentation references local scripts, conditional tool routing, and file export behavior but does not declare any explicit tool scope or allowed-tools boundary. That creates an authorization ambiguity where the agent may read or write files more broadly than intended, increasing the chance of unintended filesystem access if the runtime infers capabilities from content rather than a restrictive manifest.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The top-level description says the skill does not do AI image/video generation, but the pipeline instructs the agent to call image generation tools during visual development and storyboard creation. This discrepancy can bypass review assumptions and cause the agent to invoke media-generation tooling in contexts where operators believed such behavior was excluded.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description and main heading/content are written to activate on Chinese phrases like '帮我策划' and present the skill as a Chinese-language experience, without stating that other languages are supported or that the user may choose their preferred language. This creates a natural-language locale policy concern because the skill appears to impose a language context rather than offering one.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Later instructions direct the agent to call image generation tools despite earlier assurances that the skill is not for AI image/video generation. Contradictory instructions within a skill are risky because they undermine policy enforcement, confuse evaluators, and can lead the agent to exercise higher-risk capabilities under a misleading safety label.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file presents the skill documentation entirely in Chinese, including headings, descriptions, and operational guidance, with no indication that users may choose another language. This can violate language/locale policy when a skill imposes a specific language without explicit user opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill metadata says it is not for actual video rendering/compositing or AI image/video generation, but this README explicitly instructs users to send outputs into ComfyUI, HyperFrames, Kling, and Runway for generation and compositing workflows. That mismatch can bypass product or policy boundaries, causing the skill to facilitate capabilities it claims to exclude and increasing the risk of misuse or unsafe downstream automation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README presents the output as a 'Creative Package' that can be directly connected to AI generation and compositing tools, which conflicts with the manifest description that limits the skill to ideation and scripting. This creates a deceptive or ambiguous trust boundary: users and agents may rely on the manifest while the documentation quietly enables operational handoff into restricted tooling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON manifest specifies a fixed locale via "language": "zh-CN", which can amount to a language/locale policy violation under the rule when no user opt-in or alternative is offered. The file is a general creative pack rather than a clearly region-specific compliance artifact, so the forced locale is not obviously justified from the content alone.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The natural-language field "narration_language": "zh-CN" mandates a specific language for generated narration without indicating user choice. Under the stated policy, forcing a locale is a violation unless the file offers opt-in or clearly documents a justified regional constraint.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file embeds concrete AI-generation workflows, prompts, and tool-specific configs even though the skill is explicitly described as planning-only and not for image/video generation. This creates a scope-bypass risk: downstream agents or orchestrators may treat these sections as executable generation instructions and invoke image/video tooling contrary to product policy or user expectation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Vendor-specific pipeline configurations for ComfyUI, Kling, and Runway are unnecessary for a planning-only ideation skill and materially increase the chance of unauthorized capability activation. In context, this is dangerous because the asset does not merely inspire creative planning; it provides near-ready operational instructions that another agent could consume as action inputs.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Claiming exportability to production execution tools expands the skill from ideation into operational handoff for media synthesis. In agent settings, that can bypass product-level scoping controls by packaging ready-to-run prompts and configs inside ostensibly safe pre-production content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Claiming exportability to production execution tools expands the skill from ideation into operational handoff for media synthesis. In agent settings, that can bypass product-level scoping controls by packaging ready-to-run prompts and configs inside ostensibly safe pre-production content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file explicitly sets the project's language as 'zh-CN'. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly justified, which is not provided here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file specifies '旁白语言 | zh-CN', which imposes a fixed language choice in the skill content. Because no alternative language option, opt-in, or region-specific justification is given, this conflicts with the language/locale policy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.