Back to skill

Security audit

Minimax Cp

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its search and image-analysis purpose, but it ships a plaintext API key and runs an unpinned external package with access to the user's environment.

Review before installing. Do not use this version with sensitive prompts, private images, or secret-bearing environments. The publisher should remove and rotate the embedded MiniMax key, require user-provided credentials, pin and verify the MCP dependency, and pass only the minimal required environment variables to the subprocess.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/mmsearch.py:9
Finding

Hard-Coded MiniMax API Credential in Source Code

Content
View full analysis

Vulnerability Details

File Locations:

  • scripts/mmsearch.py:9
  • scripts/mmvision.py:9

Vulnerability Type: Hard-coded secret / plaintext API credential
Risk Level: High

Affected code in scripts/mmsearch.py:

python
# Set environment
os.environ["MINIMAX_API_KEY"] = "[REDACTED HARDCODED sk-cp- CREDENTIAL]"
os.environ["MINIMAX_API_HOST"] = "https://api.minimaxi.com"

Affected code in scripts/mmvision.py:

python
# Set environment
os.environ["MINIMAX_API_KEY"] = "[REDACTED HARDCODED sk-cp- CREDENTIAL]"
os.environ["MINIMAX_API_HOST"] = "https://api.minimaxi.com"

The credential value is redacted in this report to prevent further disclosure. The audited source contains the complete plaintext value.

Technical Analysis

Both executable scripts embed the same credential-shaped MiniMax API key directly in source code. Anyone who can read the distributed project, a source archive, repository history, logs containing the source, or a deployed copy can recover this credential without authentication.

The scripts place the credential in the global process environment. They subsequently copy that complete environment into the spawned third-party MCP process. This makes the credential accessible not only to the two scripts, but also to the dynamically executed minimax-coding-plan-mcp package.

Hard-coded secrets cannot be independently protected, rotated, or scoped per installation. Even if the key is removed from the latest source revision, it must be treated as compromised if it has appeared in any distributed version or repository history.

Attack Path

  1. An attacker obtains a copy of the Skill package or gains read access to its source.
  2. The attacker opens either scripts/mmsearch.py or scripts/mmvision.py.
  3. The attacker extracts the plaintext value assigned to MINIMAX_API_KEY.
  4. The attacker configures an external client with the extracted key and the confi ...[truncated 768 chars]
Remediation
View remediation

Remediation Suggestions

  1. Revoke the exposed credential immediately and generate a replacement. Do not merely delete it from the current files.
  2. Remove the credential from all source files, release archives, build artifacts, documentation, and version-control history.
  3. Require MINIMAX_API_KEY to be supplied through a protected runtime environment or secret manager:
    python
    api_key = os.environ.get("MINIMAX_API_KEY")
    if not api_key:
        print("MINIMAX_API_KEY is required", file=sys.stderr)
        sys.exit(1)
    
  4. Use separate, least-privilege credentials for development, testing, and production installations.
  5. Apply server-side quota, capability, expiration, and source restrictions where MiniMax supports them.
  6. Add automated secret scanning to development and release pipelines and block commits containing credential patterns.
  7. Review provider access and usage logs for unauthorized activity involving the exposed key.
  8. Avoid passing the entire parent environment to child processes. Construct a minimal environment containing only required variables.

T08 · Insecure Dependencies

Error
Location
scripts/mmsearch.py:16
Finding

Unpinned Third-Party Package Is Dynamically Resolved and Executed

Content
View full analysis

Vulnerability Details

File Locations:

  • scripts/mmsearch.py:16-23
  • scripts/mmvision.py:16-23

Vulnerability Type: Unpinned runtime dependency execution and excessive environment inheritance
Risk Level: High

Affected code in scripts/mmsearch.py:

python
# Start MCP server
proc = subprocess.Popen(
    ["uvx", "minimax-coding-plan-mcp", "-y"],
    stdin=subprocess.PIPE,
    stdout=subprocess.PIPE,
    stderr=subprocess.PIPE,
    env=os.environ.copy(),
    text=True,
    bufsize=1
)

Affected code in scripts/mmvision.py:

python
# Start MCP server
proc = subprocess.Popen(
    ["uvx", "minimax-coding-plan-mcp", "-y"],
    stdin=subprocess.PIPE,
    stdout=subprocess.PIPE,
    stderr=subprocess.PIPE,
    env=os.environ.copy(),
    text=True,
    bufsize=1
)

Technical Analysis

Both scripts invoke minimax-coding-plan-mcp through uvx without specifying an audited exact version or verifying package integrity. Runtime resolution means the code executed during a future invocation can differ from the code that was present when the Skill was reviewed.

If the upstream package, package publisher account, package registry, dependency chain, or name-resolution process is compromised, a malicious release may be retrieved and executed with the privileges of the user running the Skill.

The exposure is amplified by env=os.environ.copy(). The dynamically executed process receives the complete parent environment, including the MiniMax API credential set earlier in each script and any unrelated secrets inherited from the calling environment. Examples may include cloud credentials, access tokens, proxy credentials, and service configuration, depending on the host.

The argument list avoids direct shell-command injection because shell=True is not used and user input is not inserted into the executable name. The principal issue is supply-chain mutability and br ...[truncated 1893 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin minimax-coding-plan-mcp to a reviewed exact version rather than resolving an unconstrained release at runtime.
  2. Manage the package and all transitive dependencies with a lockfile that records exact versions and integrity hashes.
  3. Prefer installation during a controlled build or deployment phase rather than downloading and executing dependencies whenever the Skill runs.
  4. Retrieve packages only from an explicitly configured, trusted registry. Use package signature or provenance verification where available.
  5. Perform dependency vulnerability, provenance, and publisher-ownership monitoring before accepting updates.
  6. Replace broad environment inheritance with a minimal child environment. For example:
    python
    child_env = {
        "PATH": os.environ.get("PATH", ""),
        "MINIMAX_API_KEY": os.environ["MINIMAX_API_KEY"],
        "MINIMAX_API_HOST": os.environ.get(
            "MINIMAX_API_HOST",
            "https://api.minimaxi.com",
        ),
    }
    
    proc = subprocess.Popen(
        ["uvx", "--from", "minimax-coding-plan-mcp==PINNED_VERSION",
         "minimax-coding-plan-mcp", "-y"],
        stdin=subprocess.PIPE,
        stdout=subprocess.PIPE,
        stderr=subprocess.PIPE,
        env=child_env,
        text=True,
        bufsize=1,
    )
    
    The precise invocation should be validated against the supported uvx syntax and the selected package version.
  7. Run the MCP process in a sandbox with restricted filesystem and network access where feasible.
  8. Apply timeouts and robust process cleanup so a faulty or malicious dependency cannot keep the wrapper blocked indefinitely.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Even though the two TP4 entries appear contradictory, both point to the same core issue: the skill's declared capabilities do not reliably match its real behavior. That undermines trust boundaries and can hide sensitive actions such as external transmission of user data or embedded secrets, making misuse or accidental exposure more likely.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Even though the two TP4 entries appear contradictory, both point to the same core issue: the skill's declared capabilities do not reliably match its real behavior. That undermines trust boundaries and can hide sensitive actions such as external transmission of user data or embedded secrets, making misuse or accidental exposure more likely.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script hardcodes a live API credential directly in source and exports it into the process environment. Anyone with access to the code can reuse the secret for unauthorized API calls, billing abuse, or service impersonation, and embedding credentials is especially risky in a distributable skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Loading a hardcoded secret into the environment without disclosure or consent silently equips the spawned subprocess with reusable credentials. This increases the blast radius because child processes and debugging/logging paths may expose the secret, and users are not informed that the skill ships with embedded authentication material.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/mmsearch.py (reported line 22)May include surrounding context.

python
stdin=subprocess.PIPE,
        stdout=subprocess.PIPE,
        stderr=subprocess.PIPE,
        env=os.environ.copy(),
        text=True,
        bufsize=1
    )

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

A hardcoded API credential is embedded directly in the script, which exposes a live secret to anyone with repository or artifact access and enables unauthorized use of the associated external service. In a skill context, this is especially dangerous because the script is meant to be distributed and executed, making credential leakage and abuse highly likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script silently injects a hardcoded API credential into the subprocess environment, allowing downstream tooling to use sensitive credentials without any transparency or user consent. This increases the blast radius of the exposed secret and makes unintended credential use harder to detect or audit.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
92% confidence
Finding

Passing os.environ.copy() to the subprocess forwards the entire parent environment, which may include unrelated secrets, tokens, proxy settings, or credentials that the child process does not need. Because the child is an external MCP server, this unnecessarily expands the amount of sensitive data exposed to third-party code and increases impact if that dependency is compromised or behaves unexpectedly.

Content

Scanner excerpt · scripts/mmvision.py (reported line 22)May include surrounding context.

python
stdin=subprocess.PIPE,
        stdout=subprocess.PIPE,
        stderr=subprocess.PIPE,
        env=os.environ.copy(),
        text=True,
        bufsize=1
    )

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill exposes shell and environment access but does not declare any tool scope or allowed-tools restrictions. That increases the chance the skill can invoke broader local capabilities than users or the platform expect, which is especially risky because it launches external scripts and relies on environment-based secrets.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Broad trigger phrases like '搜索', '查找', or 'look up' can cause the skill to activate for ordinary conversations that the user did not intend to send to an external service. In this context, accidental invocation matters because the skill may transmit user queries or file/image references outside the local environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documentation does not warn users that search terms, image URLs, or local image paths may be transmitted to an external API. This is a real privacy and data-handling issue because users may unknowingly disclose sensitive prompts, internal file locations, or proprietary image content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest states this skill should support both search and image understanding, including an understand_image function for image analysis requests. In the actual code path, the script always builds a text query from command-line arguments and unconditionally calls the MCP tool named "web_search", with no image input handling or understand_image invocation anywhere in the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill sends the user's query to an external web-search service without any explicit user-facing notice in the code path. In a search skill this network behavior is expected, but lack of disclosure can still leak sensitive prompts or personal data to a third party when users may assume local processing.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/mmsearch.py (reported line 17)May include surrounding context.

python
"""Call MCP tool via stdio"""
    
    # Start MCP server
    proc = subprocess.Popen(
        ["uvx", "minimax-coding-plan-mcp", "-y"],
        stdin=subprocess.PIPE,
        stdout=subprocess.PIPE,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/mmvision.py (reported line 17)May include surrounding context.

python
"""Call MCP tool via stdio"""
    
    # Start MCP server
    proc = subprocess.Popen(
        ["uvx", "minimax-coding-plan-mcp", "-y"],
        stdin=subprocess.PIPE,
        stdout=subprocess.PIPE,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script launches an external command via subprocess to start the MCP server, which is a safety-relevant action for code files. Although there is an internal comment, there is no user-visible disclosure such as a prompt, print statement, or documented warning that an external process will be executed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes a skill that should handle both webpage search and image understanding, including search-related trigger phrases. This file's actual user-facing behavior only invokes the "understand_image" MCP tool and contains no implementation of any search capability, creating a mismatch between the claimed scope and the delivered behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

User-supplied prompt text and image sources are sent to an external service, which can expose sensitive data contained in images, URLs, or prompts if users are unaware of the transfer. In an image-understanding skill, remote transmission is contextually expected, but the lack of clear disclosure still creates a privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
73% confidence
Finding

The natural-language description, usage guidance, and trigger definitions are presented only in Chinese, while also embedding a few English trigger words. This can constitute a language policy issue if users are not explicitly offered a language or locale choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The only natural-language examples shown to the user are Chinese prompt strings, which imposes a specific language in the usage guidance without any opt-in or mention that other languages are acceptable. This can be interpreted as a language policy issue because the script does not offer language choice or justify the locale constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.