Back to skill

Security audit

TencentCloud Video Face Fusion

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real Tencent Cloud face-fusion helper, but it needs review because it can upload biometric media without confirmation, read local files passed as images, and auto-install an unpinned package.

Install only if you are comfortable sending face images and video material to Tencent Cloud under your own Tencent credentials. Use it with explicit user consent for all faces and videos, keep the AI-generated label enabled unless there is a legitimate reason, avoid passing untrusted local paths, run it in a restricted environment, and preinstall a pinned Tencent SDK instead of allowing runtime pip installation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/main.py:91
Finding

Unrestricted Local File Reading and Transmission Through Image Arguments

Content
View full analysis
100 and "/" not in value and "\\" not in value: return {"Base64": value} ``` The data is placed into the API request at `scripts/submit_job.py:145-165`: ```python for i, (tpl_input, face_input) in enumerate(zip(template_images, face_images)): f ...[truncated 3151 chars]
Remediation
View remediation
MAX_IMAGE_SIZE: raise ValueError("Image exceeds the 10 MB limit") ``` 4. Validate content using JPEG and PNG magic bytes and a maintained image parser. Verify the decoded format and dimensions rather than trusting the extension. 5. Read with a strict size bound instead of unconditionally calling `f.read()`. 6. Require explicit approval before uploading a local file, particularly when its path originated from untrusted conversational content. 7. Clearly disclose that local image contents are transmitted to Tencent Cloud for processing. 8. Prefer presigned, user-controlled URLs where appropriate, while applying URL validation and access controls. ]]>

T08 · Insecure Dependencies

Warning
Location
scripts/main.py:15
Finding

Automatic Installation of an Unpinned Runtime Dependency

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The top-level description understates the actual behavior: this is not just simple two-face fusion but a cloud-backed video face-swap workflow with credential use and network submission. Misdescribing a skill's true capability can mislead users and agent frameworks, causing sensitive biometric processing and external data transfer without informed understanding.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The top-level description understates the actual behavior: this is not just simple two-face fusion but a cloud-backed video face-swap workflow with credential use and network submission. Misdescribing a skill's true capability can mislead users and agent frameworks, causing sensitive biometric processing and external data transfer without informed understanding.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly tells the agent to perform face-fusion automatically, without confirmation, despite processing highly sensitive biometric data and potentially uploading user media to a third-party cloud service. This removes an important consent checkpoint and materially increases the risk of privacy violations, misuse, and non-compliant handling of identity-related data.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares executable behavior involving shell commands and environment-secret use, but does not define any explicit tool scope or permission boundaries. That omission increases the chance an agent will execute scripts or access credentials more broadly than intended, especially because the document instructs autonomous execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation includes an option to disable the AI-generated content logo without any guardrails, disclosure requirements, or abuse warnings. In a face-fusion/deepfake context, hiding provenance can facilitate deception, impersonation, and distribution of unlabeled synthetic media.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/submit_video_face_fusion_api.md (reported line 14)May include surrounding context.

md
## 输入参数

| 参数名称        | 必选 | 类型                     | 描述                                                                                                                                                    |
| --------------- | ---- | ------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------- |
| VideoUrl        | 是   | String                   | 视频素材下载地址。分辨率≤4k,fps≤25,大小≤1G,时长≤20秒,支持 mp4 格式。                                                                                     |
| TemplateInfos   | 是   | Array of FaceTemplateInfo | 视频素材模板的人脸位置信息。最多支持融合视频中 6 张人脸。                                                                                                     |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/submit_video_face_fusion_api.md (reported line 16)May include surrounding context.

md
| 参数名称        | 必选 | 类型                     | 描述                                                                                                                                                    |
| --------------- | ---- | ------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------- |
| VideoUrl        | 是   | String                   | 视频素材下载地址。分辨率≤4k,fps≤25,大小≤1G,时长≤20秒,支持 mp4 格式。                                                                                     |
| TemplateInfos   | 是   | Array of FaceTemplateInfo | 视频素材模板的人脸位置信息。最多支持融合视频中 6 张人脸。                                                                                                     |
| MergeInfos      | 是   | Array of FaceMergeInfo   | 用户人脸图片位置信息。图片≤10MB,分辨率≤4k,建议最小 128,人脸框最小 68,支持 jpg/png。                                                                         |
| LogoAdd         | 否   | Integer                  | 是否添加 AI 合成标识。默认 1(添加)。0:不添加,1:添加。                                                                                                     |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The API documentation explicitly requires uploading user face images and video URLs, which involves biometric data and potentially sensitive personal media, but it provides no warning or requirements around informed consent, lawful basis, retention, access control, or secure handling. In a face-fusion context, this omission is materially risky because developers may implement collection and processing flows without privacy safeguards, enabling misuse, non-consensual deepfake generation, or regulatory noncompliance.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/submit_video_face_fusion_api.md (reported line 17)May include surrounding context.

md
| 参数名称        | 必选 | 类型                     | 描述                                                                                                                                                    |
| --------------- | ---- | ------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------- |
| VideoUrl        | 是   | String                   | 视频素材下载地址。分辨率≤4k,fps≤25,大小≤1G,时长≤20秒,支持 mp4 格式。                                                                                     |
| TemplateInfos   | 是   | Array of FaceTemplateInfo | 视频素材模板的人脸位置信息。最多支持融合视频中 6 张人脸。                                                                                                     |
| MergeInfos      | 是   | Array of FaceMergeInfo   | 用户人脸图片位置信息。图片≤10MB,分辨率≤4k,建议最小 128,人脸框最小 68,支持 jpg/png。                                                                         |
| LogoAdd         | 否   | Integer                  | 是否添加 AI 合成标识。默认 1(添加)。0:不添加,1:添加。                                                                                                     |
| LogoParam       | 否   | LogoParam                | 视频水印 Logo 参数。默认右下角添加"AI生成"字样。                                                                                                               |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/submit_video_face_fusion_api.md (reported line 19)May include surrounding context.

md
| 参数名称        | 必选 | 类型                     | 描述                                                                                                                                                    |
| --------------- | ---- | ------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------- |
| VideoUrl        | 是   | String                   | 视频素材下载地址。分辨率≤4k,fps≤25,大小≤1G,时长≤20秒,支持 mp4 格式。                                                                                     |
| TemplateInfos   | 是   | Array of FaceTemplateInfo | 视频素材模板的人脸位置信息。最多支持融合视频中 6 张人脸。                                                                                                     |
| MergeInfos      | 是   | Array of FaceMergeInfo   | 用户人脸图片位置信息。图片≤10MB,分辨率≤4k,建议最小 128,人脸框最小 68,支持 jpg/png。                                                                         |
| LogoAdd         | 否   | Integer                  | 是否添加 AI 合成标识。默认 1(添加)。0:不添加,1:添加。                                                                                                     |
| LogoParam       | 否   | LogoParam                | 视频水印 Logo 参数。默认右下角添加"AI生成"字样。                                                                                                               |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/submit_video_face_fusion_api.md (reported line 20)May include surrounding context.

md
| TemplateInfos   | 是   | Array of FaceTemplateInfo | 视频素材模板的人脸位置信息。最多支持融合视频中 6 张人脸。                                                                                                     |
| MergeInfos      | 是   | Array of FaceMergeInfo   | 用户人脸图片位置信息。图片≤10MB,分辨率≤4k,建议最小 128,人脸框最小 68,支持 jpg/png。                                                                         |
| LogoAdd         | 否   | Integer                  | 是否添加 AI 合成标识。默认 1(添加)。0:不添加,1:添加。                                                                                                     |
| LogoParam       | 否   | LogoParam                | 视频水印 Logo 参数。默认右下角添加"AI生成"字样。                                                                                                               |

### FaceTemplateInfo 结构

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/submit_video_face_fusion_api.md (reported line 24)May include surrounding context.

md
### FaceTemplateInfo 结构

| 参数名称           | 必选 | 类型     | 描述                                                                                             |
| ------------------ | ---- | -------- | ------------------------------------------------------------------------------------------------ |
| TemplateFaceID     | 否   | String   | 角色 ID。需与 MergeInfos 中的 TemplateFaceID 对应。建议填 "0"、"1" 依次累加。                        |
| TemplateFaceImage  | 是   | Image    | 视频模板中要替换的人脸图片。                                                                         |

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Installing Python packages at runtime grants the skill an unexpected capability beyond its stated business function and creates supply-chain exposure. This is especially risky in agent or sandboxed environments because execution of package installation can fetch and run untrusted code from external repositories, broadening the attack surface.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
95% confidence
Finding

The script executes pip at runtime to install a dependency, which introduces a software supply-chain and execution risk. Even though the command is not shell-injected and uses a fixed package name, it still allows network-based code retrieval and installation during execution, which is unnecessary in many controlled environments and can violate least-privilege expectations for a face-fusion skill.

Content

Scanner excerpt · scripts/main.py (reported line 20)May include surrounding context.

python
import tencentcloud  # noqa: F401
    except ImportError:
        print("[INFO] tencentcloud-sdk-python not found. Installing...", file=sys.stderr)
        subprocess.check_call(
            [sys.executable, "-m", "pip", "install", "tencentcloud-sdk-python", "-q"],
            stdout=sys.stderr,
            stderr=sys.stderr,

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Installing Python packages at runtime is not justified by this skill's narrow purpose of querying job status, so the capability is broader than necessary. This increases attack surface by permitting network access, package resolution, and execution of third-party install hooks during normal operation, creating avoidable supply-chain risk and reducing reproducibility of the environment.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
91% confidence
Finding

The script executes pip at runtime to install a package when an import fails. Although the command is not shell-injected, it introduces a software supply-chain and environment-mutation risk: execution now depends on live package resolution and whatever package/index configuration exists on the host, which is unnecessary for a read-only job-status query tool. In agent or production environments, this can lead to unreviewed code being fetched and executed with the script's privileges.

Content

Scanner excerpt · scripts/query_job.py (reported line 17)May include surrounding context.

python
import tencentcloud  # noqa: F401
    except ImportError:
        print("[INFO] tencentcloud-sdk-python not found. Installing...", file=sys.stderr)
        subprocess.check_call(
            [sys.executable, "-m", "pip", "install", "tencentcloud-sdk-python", "-q"],
            stdout=sys.stderr,
            stderr=sys.stderr,

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Installing Python packages at runtime is not required for the business logic of submitting a Tencent Cloud face-fusion job and expands the script's behavior beyond its declared purpose. This creates avoidable supply-chain exposure, permits unexpected network access and code execution during startup, and can be abused in restricted or sensitive environments.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
92% confidence
Finding

The script automatically installs a Python package at runtime via pip before performing its stated task. Runtime package installation introduces a supply-chain and execution risk because it reaches out to external package infrastructure and executes installer-controlled code in the current environment, which is unnecessary for safe operation of a face-fusion submission helper.

Content

Scanner excerpt · scripts/submit_job.py (reported line 19)May include surrounding context.

python
import tencentcloud  # noqa: F401
    except ImportError:
        print("[INFO] tencentcloud-sdk-python not found. Installing...", file=sys.stderr)
        subprocess.check_call(
            [sys.executable, "-m", "pip", "install", "tencentcloud-sdk-python", "-q"],
            stdout=sys.stderr,
            stderr=sys.stderr,

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The top-level documentation states the script submits a job and automatically polls until complete. In practice, --no-poll at L142-L144 and the early return at L296-L303 allow submission without polling, which contradicts the stated behavior rather than merely omitting detail.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The credential setup guide uses Chinese text for steps 1 and 2, which imposes a specific language in user-facing output. The file does not offer an alternative language or ask for user language preference, so this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.