Back to skill

Security audit

Minimax Web Search

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to provide the advertised MiniMax search and image-analysis features, but it bundles an API key and runs unpinned external code with broad environment access, so it needs Review before installation.

Install only after the publisher removes and rotates the bundled MiniMax API key, pins or vendors the MCP dependency, passes a minimal environment to subprocesses, and clearly discloses that search terms, prompts, image paths, image URLs, and possibly image content are processed by an external service.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/mmsearch.py:8
Finding

Hard-Coded MiniMax API Credential in Search Script

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/mmvision.py:8
Finding

Hard-Coded MiniMax API Credential in Vision Script

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/mmsearch.py:16
Finding

Unpinned Runtime Package Execution in Search Script

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/mmvision.py:16
Finding

Unpinned Runtime Package Execution in Vision Script

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the skill claims search capability but actually only performs image understanding, or vice versa, the mismatch can cause the agent to invoke the wrong workflow and send unintended user data to an external API. The finding is more serious because it also indicates undisclosed API credential use, which is a sensitive behavior outside the stated purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the skill claims search capability but actually only performs image understanding, or vice versa, the mismatch can cause the agent to invoke the wrong workflow and send unintended user data to an external API. The finding is more serious because it also indicates undisclosed API credential use, which is a sensitive behavior outside the stated purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script hard-codes a live MiniMax API key directly into source and exports it into the runtime environment. Anyone with file access can recover and abuse the credential, leading to unauthorized API usage, billing abuse, and possible access to associated account resources.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

A hard-coded API credential is not only present but also propagated into a subprocess environment with no disclosure to the user. This increases exposure because child processes and related diagnostics may access the secret, broadening the blast radius of the credential leak.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
95% confidence
Finding

Using os.environ.copy() forwards the entire parent environment to the subprocess, which can expose unrelated secrets, tokens, and internal configuration to external tooling. In this skill context, that is more dangerous because the skill already injects an API key and then launches a third-party MCP process, unnecessarily expanding access to sensitive data.

Content

Scanner excerpt · scripts/mmsearch.py (reported line 22)May include surrounding context.

python
stdin=subprocess.PIPE,
        stdout=subprocess.PIPE,
        stderr=subprocess.PIPE,
        env=os.environ.copy(),
        text=True,
        bufsize=1
    )

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

A live MiniMax API key is hardcoded directly in the script and exported into the process environment. Anyone with access to the code can reuse the credential, and any downstream process or logs that expose environment variables may leak it further, enabling unauthorized API use and billing abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script silently injects a hardcoded API key into the environment without disclosure to the user. This hides credential use, makes secret exposure easier during debugging or child-process inspection, and normalizes unsafe secret handling in a tool whose stated purpose does not require bundled credentials.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/mmvision.py (reported line 22)May include surrounding context.

python
stdin=subprocess.PIPE,
        stdout=subprocess.PIPE,
        stderr=subprocess.PIPE,
        env=os.environ.copy(),
        text=True,
        bufsize=1
    )

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises executable shell commands and use of environment-backed secrets but does not declare any explicit tool scope such as allowed-tools or permissions. That makes the runtime authority ambiguous and increases the risk of over-broad execution, especially for a skill that can invoke scripts and contact external services.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Broad triggers like common words for search or image analysis can cause unintended invocation during normal conversation, leading to unexpected shell/script execution or external API calls. In this skill's context, accidental activation is more dangerous because user queries or image references may be transmitted to a third-party service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documentation does not warn users that search terms, image URLs, or image content may be sent to an external API for processing. This lack of transparency can expose sensitive user data or internal URLs without informed consent, particularly when the skill processes arbitrary image paths or remote image links.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script launches an external MCP server via subprocess, which is a safety-relevant operation under this rule set. Although there is an internal comment, there is no confirmation prompt, visible print/log message, or broader user disclosure explaining that an external command will be executed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest says the skill should support both searching and image analysis depending on user intent, including an understand_image function. In this file, the CLI always invokes only the web_search tool and accepts only a text query, so the implemented behavior is narrower than the declared skill description.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/mmsearch.py (reported line 17)May include surrounding context.

python
"""Call MCP tool via stdio"""
    
    # Start MCP server
    proc = subprocess.Popen(
        ["uvx", "minimax-coding-plan-mcp", "-y"],
        stdin=subprocess.PIPE,
        stdout=subprocess.PIPE,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/mmvision.py (reported line 17)May include surrounding context.

python
"""Call MCP tool via stdio"""
    
    # Start MCP server
    proc = subprocess.Popen(
        ["uvx", "minimax-coding-plan-mcp", "-y"],
        stdin=subprocess.PIPE,
        stdout=subprocess.PIPE,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The tool sends the user-provided image source and prompt to an external MiniMax MCP service, but there is no user-facing notice or consent flow indicating that image data may leave the local system. In an image-understanding skill, this is especially relevant because images may contain sensitive personal, business, or location information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The skill's natural-language description, trigger phrases, headings, and examples are primarily presented in Chinese, while also including some English trigger terms. This may implicitly constrain usage to a specific language/locale without documenting that choice or offering an explicit language option.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Mentioning an API key dependency without warning that the skill uses a credentialed external service hides an important trust boundary from users and reviewers. While weaker than direct secret exposure, it still creates a transparency and governance issue around third-party processing and billing-backed access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The only user-facing examples are Chinese prompt strings, which implicitly steer usage toward a specific language. There is no accompanying note that other languages are supported or that the language requirement is intentional and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.