Back to skill

Security audit

MiniMax H3 Studio

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese MiniMax H3 creative workflow pack with no executable installer, though users should review its Chinese-output and MiniMax-H3 defaults before use.

Install only if you want a Chinese-first MiniMax H3 creative workflow pack. Before generating media, explicitly confirm the provider/model, language, budget, uploaded assets, and whether broad replies like continue should count as approval.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Vague Triggers

Medium
Confidence
80% confidence
Finding
The skill metadata is broadly phrased and does not define clear activation boundaries or narrow task triggers, which can cause the agent to invoke this skill in contexts beyond the author’s intended scope. In practice, ambiguous routing increases the chance of prompt confusion, unintended tool selection, or misuse of downstream connected generation/synthesis capabilities.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The default prompt hard-codes all-Chinese output regardless of user preference, which overrides user autonomy and can degrade safety or usability when users expect another language. This is mainly a policy/UX control issue, but it can also interfere with accurate interpretation, review, or moderation in multilingual environments.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The extraction triggers include broad natural-language examples such as 'let me focus on S05' and 'S05 needs rework', which can match ordinary conversational feedback and cause unintended state changes in the workflow. In an agentic system, ambiguous trigger phrases can be exploited or accidentally invoked to redirect processing, fragment artifacts, or alter which storyboard node downstream steps consume.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The guideline hard-codes Chinese identifiers in binding markers and examples, which can override or distort user-provided naming conventions and cause incorrect card binding in multilingual projects. Because later generation steps depend on exact character and scene names, forcing a naming format without opt-in can create reference mismatches, continuity errors, or unintended asset selection.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The extraction trigger examples are broad enough that ordinary review comments like 'let me focus on S05' or 'S05 needs rework' could be interpreted as state-changing commands rather than discussion. In an agent workflow, that ambiguity can cause unintended document mutation, mode switching, or incorrect pipeline inputs without explicit confirmation, which is a real control-flow vulnerability even if not security-critical in the classic sense.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill treats broad conversational phrases like 'continue', 'next', and similar equivalents as authorization to start generation after showing a pre-production package. In a chat workflow, those phrases are often used to advance discussion rather than to grant consent for potentially costly or policy-sensitive actions, so the agent may generate assets without clear, informed approval.

Natural-Language Policy Violations

Medium
Confidence
98% confidence
Finding
The prompt template contains an explicit gender-based exclusion: 'no female character unless explicitly requested by user.' This introduces biased default behavior and can cause discriminatory outputs when users do not request any gender constraint, which is especially problematic in a general-purpose creative generation workflow.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs the agent to output in Chinese and says English examples do not override the unified Chinese rules, which can override or conflict with a user's language preference. This is not a classic security exploit, but it is a prompt-policy vulnerability because it reduces user control and can cause the agent to ignore user intent or higher-level product expectations about language selection.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill mandates English rewrite sections without requiring user consent, which can override user intent and create unsafe or policy-conflicting transformations in multilingual workflows. In an agent setting, forced language conversion can also cause data-handling mistakes, loss of nuance, or unintended disclosure when text should remain in the original language.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The skill explicitly requires all user-visible prompts to use Chinese and does not provide a mechanism to honor the user's preferred language. This can cause instruction mismatch, reduce usability, and create safety/compliance issues when users expect outputs in another language or rely on precise multilingual handling.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill hard-codes a language constraint requiring all visible on-screen ad copy to be English, even though the broader workflow claims to respect user-specified language. This can override user intent or locale requirements and cause unauthorized content transformation, which is a policy and trust issue rather than a classic security exploit.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The workflow explicitly instructs the agent to read and follow a separate unified Chinese-output specification and states that prompt body and structure must be in Chinese. This can override or constrain a user's language preference, creating a policy/UX control issue where the agent may ignore user-directed output language or accessibility needs.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The skill explicitly defaults to MiniMax-H3 for actual video generation unless the user overrides it. This removes explicit user opt-in for model selection and can steer execution into a specific provider, which may have cost, privacy, compliance, or capability implications the user did not knowingly accept.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill instructs the agent to choose culturally specific background music for certain topics by default, using examples like traditional Chinese instruments for Mid-Autumn Festival content, without first requiring explicit user preference or consent. This can steer outputs toward cultural assumptions or stereotyping, and may produce sensitive or inappropriate creative choices when the user's audience, brand, or educational context calls for a neutral or different treatment.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The skill explicitly mandates Chinese output and states that Chinese structure and wording take precedence before processing the workflow. This can override or constrain a user's requested language, reducing user control and potentially causing downstream misuse when other tools or users expect output in a different language.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The file explicitly mandates Chinese for正文、标题、切镜句和运镜语言 by default, except for limited exceptions. This can override user language preference and cause the agent to ignore or reshape user instructions, which is a policy/control-flow issue rather than a code execution flaw; the surrounding context is a formatting guide, so the danger is limited to unwanted behavior and reduced user control.

Static analysis

No suspicious patterns detected.