Back to skill

Security audit

Meteor Master AI Bridge

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent bridge for Meteor Master AI, but it exposes sensitive stream/local metadata and supports irreversible bulk changes without enough guardrails.

Install only if you trust the mma-bridge npm package and Meteor Master AI instance. Avoid administrator installs, pin or verify the npm package where possible, and require explicit user confirmation before delete, collect, uncollect, analyze, or export actions. Treat getCurrentInfo and getDataDetail output as sensitive because it may include camera stream credentials, local file paths, proxy settings, coordinates, and device metadata.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Error
Location
SKILL.md:60
Finding

Unpinned Global npm Dependency Creates a Supply-Chain Execution Risk

Content
View full analysis
Remediation
View remediation
``` 6. Perform installation as an unprivileged user and avoid `sudo` or an administrator shell. 7. Establish a controlled update process in which new versions are reviewed before the Skill recommends them. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
references/getCurrentInfo.md:38
Finding

Current-Information API Returns Plaintext Stream Credentials and Sensitive Local Metadata

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/deleteGroup.md:23
Finding

Irreversible Batch Deletion Is Documented Without a Mandatory Confirmation Control

Content
View full analysis
data.json mma post --method deleteGroup --data-file data.json ``` The documentation explicitly states at `references/deleteGroup.md:149` that deletion is irreversible. ### Technical Analysis The API permits deletion of multiple records in one request and the documented workflow submits the destructive request immediately after writing the IDs to a JSON file. It does not require a confirmation token, preview, dry-run operation, maximum batch size, backup, or record-version check. A warning that deletion is irreversible does not provide an enforcement boundary. In an agent-operated environment, ambiguous user language, an incorrectly generated filter, stale IDs, or prompt manipulation could therefore result in permanent deletion without the user seeing the exact affected records. The requirement that IDs originate from `getDataList` reduces malformed-ID risk but does not establish that the intended records were selected or that the user approved the final deletion scope. ### Attack Path 1. The agent calls `getDataList` and receives valid record IDs. 2. Through an ambiguous request, selection error, stale context, or manipulated instruction, the agent places unintended IDs into the `ids` array. 3. The agent writes the request to a JSON file. 4. The agent invokes: ```bash mma post --method deleteGroup --data-file data.json ``` 5. The API deletes valid records ...[truncated 639 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (20)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The natural-language instructions are written to direct future conversation behavior around Meteor Master AI terminology and are presented only in Chinese, including mandatory phrasing like '请确保' and '尽量使用全称'. This imposes a language/locale preference without explicitly offering the user a choice or opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file documents that mma list will '删除无响应或响应无效的实例文件', which is a file-deletion operation that can affect the local system state. The description does not provide a user-facing warning or caution about this cleanup behavior or its implications.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation is entirely in Chinese with no language selection or opt-in, which can prevent non-Chinese-speaking users or reviewers from understanding operational constraints, side effects, and failure conditions. In a security-sensitive agent ecosystem, unreadable documentation increases the chance of misuse, unsafe execution, and missed review findings because users may invoke the API without understanding what local folder paths and image-processing behavior imply.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file presents all user-facing descriptive content, parameters, responses, and cautions in Chinese only. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified, which this document does not provide.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Nearly all user-facing documentation is written in Chinese, with no indication that the skill is region-specific or that another language option is available. Under the stated policy, forcing a specific language without user opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The markdown content is written entirely in Chinese, including headings, parameter descriptions, examples, and response explanations, with no indication that the user can choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the regional constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file’s natural-language instructions, examples, and warnings are entirely in Chinese, and there is no indication that the skill is region-specific or that users can opt into this language. Under the policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The documentation explicitly allows writing an exported image to an arbitrary user-specified directory or JPG file path, but provides no warning about overwrite behavior, path safety, or filesystem side effects. In a bridge/agent context, this can lead to unintended file creation or overwriting if an agent passes unsafe paths, especially because the examples encourage direct use of absolute paths.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file uses only Chinese for its description, commands context, and field explanations. Under the policy for natural-language violations, forcing a specific language without user opt-in is a reportable issue unless the locale constraint is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documentation is written entirely in Chinese, including operational instructions, parameter descriptions, examples, and notes, with no indication that language selection is optional or that the skill is region-specific. This can constitute a language/locale policy violation under the rule for natural-language policy concerns.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation describes an operation that removes saved user state (favorites) for one or many records, but it does not clearly warn that this is a state-changing/destructive action. In an agent skill context, especially with batch support, missing cautionary language increases the risk of unintended bulk modifications by users or downstream agents that may treat the command as routine retrieval rather than mutation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

L178-L188 明确声明 mma post 统一调用格式必须包含 --data-file,且 L188 强调即使传空对象也必须提供该参数。但 L219-L221 的示例却展示了 mma post --method getCurrentInfo,未传 --data-file。这属于文档内部对实际使用方式的主动矛盾,可能误导调用方。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The markdown states that after checking the video information, analysis starts automatically. It does not explicitly warn users up front that providing a file path will trigger immediate processing of the file, which is a behavior affecting user data handling and should be disclosed clearly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. This file presents the operational instructions entirely in Chinese, with no user opt-in, alternative language option, or justification that the skill is intended only for a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documented API response includes local file paths, exported media locations, source filenames, and EXIF camera metadata, all of which can reveal sensitive host, filesystem, and device details to users of the skill. While this is an informational disclosure issue rather than active code execution, the documentation omits any warning or guidance about handling this sensitive output, increasing the risk of accidental exposure or unsafe downstream logging/sharing.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

L032-L039 明确说明 type 的可选值包含 0,且示例请求在 L019 和 L050/L059 也实际使用了 0 表示流星。L173 却写成“必须在 1-6 之间”,这会把前文定义的合法值 0 排除掉,属于文档对接口行为的直接自相矛盾。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documentation is written entirely in Chinese, beginning with the section heading and description, with no indication that users may choose another language or that the locale restriction is intentional. Under the language/locale policy rule, forcing a specific language without opt-in or justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

L237 说明 command 是“用于排序的具体值,即排序字段名”,暗示其应为字符串字段名;但示例响应在 L129、L133、L141、L149、L157、L165、L173 中均将 command 表示为整数 0-6。该文档说明与其展示的实际接口行为直接矛盾,属于文档意图与内容不一致。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. The natural-language instructions and examples are entirely Chinese, with no opt-in, alternative language, or statement that the skill is intentionally limited to a Chinese-speaking or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's natural-language instructions and descriptions are entirely in Chinese, with no indication that language selection is optional or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.