Back to skill

Security audit

HY 3D Generation

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to do Tencent Cloud 3D generation as advertised, but it should be reviewed because it automatically installs an unpinned SDK at runtime while cloud credentials may be present.

Install only if you are comfortable sending generation inputs to Tencent Cloud and can run it in an isolated environment with short-lived, least-privilege Tencent credentials. Preinstall a pinned, reviewed Tencent SDK instead of allowing runtime pip installation, and avoid placing long-lived secrets in shell startup files on shared machines.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/main.py:14
Finding

Unpinned Automatic Runtime Dependency Installation

Content
View full analysis

Vulnerability Details

File Locations:

  • scripts/main.py:14-23
  • scripts/submit_job.py:13-22
  • scripts/query_job.py:14-23

Vulnerability Type: Uncontrolled third-party dependency installation
Risk Level: Medium

Affected code in scripts/main.py:

python
def ensure_dependencies():
    try:
        import tencentcloud.ai3d  # noqa: F401
    except (ImportError, ModuleNotFoundError):
        print("[INFO] tencentcloud-sdk-python (ai3d) not found. Installing...", file=sys.stderr)
        subprocess.check_call(
            [sys.executable, "-m", "pip", "install", "tencentcloud-sdk-python", "-q"],
            stdout=sys.stderr,
            stderr=sys.stderr,
        )
        print("[INFO] tencentcloud-sdk-python installed successfully.", file=sys.stderr)

Affected code in scripts/submit_job.py:

python
def ensure_dependencies():
    try:
        import tencentcloud.ai3d  # noqa: F401
    except (ImportError, ModuleNotFoundError):
        print("[INFO] tencentcloud-sdk-python (ai3d) not found. Installing...", file=sys.stderr)
        subprocess.check_call(
            [sys.executable, "-m", "pip", "install", "tencentcloud-sdk-python", "-q"],
            stdout=sys.stderr,
            stderr=sys.stderr,
        )
        print("[INFO] tencentcloud-sdk-python installed successfully.", file=sys.stderr)

Affected code in scripts/query_job.py:

python
def ensure_dependencies():
    try:
        import tencentcloud.ai3d  # noqa: F401
    except (ImportError, ModuleNotFoundError):
        print("[INFO] tencentcloud-sdk-python (ai3d) not found. Installing...", file=sys.stderr)
        subprocess.check_call(
            [sys.executable, "-m", "pip", "install", "tencentcloud-sdk-python", "-q"],
            stdout=sys.stderr,
            stderr=sys.stderr,
        )
        print("[INFO] tencentcloud-sdk-python installed successfully.", 
...[truncated 2664 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove automatic dependency installation from all executable scripts. If the SDK is unavailable, terminate with a clear error that directs the operator to the documented installation procedure.
  2. Declare an exact, reviewed SDK version in project dependency metadata rather than resolving the latest release:
    text
    tencentcloud-sdk-python==<audited-version>
    
  3. Generate and commit a lockfile containing cryptographic hashes. Install dependencies during a controlled deployment stage with hash verification, such as:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  4. Use a trusted, explicitly configured HTTPS package index or an internally controlled artifact repository.
  5. Perform dependency installation in an isolated virtual environment or container under a least-privilege account.
  6. Add automated dependency vulnerability and integrity scanning to the release process.
  7. Use short-lived Tencent Cloud credentials with narrowly scoped permissions so dependency compromise cannot expose long-lived or broadly privileged credentials.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是“生成3D模型”的主能力,强调多种输入模式和模型生成功能;但提供的代码仅调用 QueryHunyuanTo3DProJob 接口,对已有任务进行状态查询和轮询,最终返回结果文件信息。代码中没有任何上传文本、图片、多视图或草图输入,也没有提交生成任务的逻辑,因此其主要目的与声明明显不符。自动安装 SDK、读取环境变量凭证属于实现细节,但访问腾讯云 AI3D 查询接口这一资源使用也与“仅描述生成能力”存在明显行为差异。总体应判定为描述与实际代码行为不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill exposes shell and environment-variable capabilities but does not declare any explicit tool scope or permission boundaries. That increases the chance an agent can execute commands and access secrets more broadly than intended, making credential exposure or unintended command execution easier if the skill is invoked in a permissive runtime.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs the agent to send user-provided text or image inputs to a third-party cloud API without asking for confirmation. This can cause unintended disclosure of sensitive prompts, private images, or regulated data, especially when users may not realize their content will be transmitted externally.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Installing Python packages at runtime gives the skill code-execution and environment-modification capability that is not necessary for handling user prompts or images for 3D generation. In this context, the danger is elevated because the skill runs in an agent environment where dynamic installation can pull unreviewed code, alter shared environments, and bypass normal dependency review controls.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
95% confidence
Finding

The script invokes pip at runtime to install a package if the dependency is missing, which executes external code and mutates the host environment during normal skill execution. Even though the command arguments are hardcoded and there is no shell injection here, runtime package installation expands the skill's behavior beyond 3D generation and creates supply-chain and integrity risks if package sources, mirrors, or the environment are compromised.

Content

Scanner excerpt · scripts/main.py (reported line 19)May include surrounding context.

python
import tencentcloud.ai3d  # noqa: F401
    except (ImportError, ModuleNotFoundError):
        print("[INFO] tencentcloud-sdk-python (ai3d) not found. Installing...", file=sys.stderr)
        subprocess.check_call(
            [sys.executable, "-m", "pip", "install", "tencentcloud-sdk-python", "-q"],
            stdout=sys.stderr,
            stderr=sys.stderr,

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Installing Python packages at runtime is unsafe in this context because it expands the skill's behavior from querying job status to downloading and executing external code, creating avoidable supply-chain risk. In an agent skill, this is more dangerous because the code may run in privileged or shared environments where unexpected package installation can alter state, pull malicious dependencies, or bypass deployment controls.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
94% confidence
Finding

The script executes a runtime pip installation via subprocess, which introduces a supply-chain and arbitrary code execution risk because package installation runs untrusted setup/build logic in the current environment. Even though the package name is hardcoded and there is no shell injection here, a skill whose purpose is only to query 3D job status does not need to mutate the host or fetch code from the network at execution time.

Content

Scanner excerpt · scripts/query_job.py (reported line 19)May include surrounding context.

python
import tencentcloud.ai3d  # noqa: F401
    except (ImportError, ModuleNotFoundError):
        print("[INFO] tencentcloud-sdk-python (ai3d) not found. Installing...", file=sys.stderr)
        subprocess.check_call(
            [sys.executable, "-m", "pip", "install", "tencentcloud-sdk-python", "-q"],
            stdout=sys.stderr,
            stderr=sys.stderr,

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Installing Python packages at runtime is not necessary for submitting a 3D generation job and introduces avoidable supply-chain risk. In this skill context, the behavior is more dangerous because the skill handles cloud credentials, so a compromised dependency or install path could execute attacker-controlled code in an environment where API secrets are present.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
94% confidence
Finding

The script automatically executes pip install at runtime when the dependency is missing. Although it does not invoke a shell and installs a fixed package name, it still causes network access and code installation/execution from an external package index during normal skill use, which expands the trust boundary and can be abused through dependency confusion, malicious mirrors, or compromised package supply chain.

Content

Scanner excerpt · scripts/submit_job.py (reported line 18)May include surrounding context.

python
import tencentcloud.ai3d  # noqa: F401
    except (ImportError, ModuleNotFoundError):
        print("[INFO] tencentcloud-sdk-python (ai3d) not found. Installing...", file=sys.stderr)
        subprocess.check_call(
            [sys.executable, "-m", "pip", "install", "tencentcloud-sdk-python", "-q"],
            stdout=sys.stderr,
            stderr=sys.stderr,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The argument help string says 'Chinese recommended,' which nudges users toward a specific language/locale choice. The policy allows locale constraints only when justified or when the user is given an explicit choice, neither of which is stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The argument help string says "Chinese recommended," which nudges users toward a specific language/locale choice without offering an explicit opt-in or alternative. This is a natural-language policy concern because it imposes a language preference in user-facing text rather than leaving the choice neutral.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.