Back to skill

Security audit

即梦AI视频生成

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Dreamina/Volcengine video-generation skill, but users should understand that prompts and media requests go to an external paid API.

Before installing, confirm you are comfortable sending prompts, image inputs, and generation metadata to Volcengine/Dreamina and potentially incurring API charges. Do not include secrets, regulated data, or confidential business material in prompts, and keep the Volcengine access keys protected. Because the triggers include broad video-generation phrases, prefer explicit invocation when you intend to use this provider.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The README instructs use of a remote API endpoint with bearer-token authentication, meaning prompts and possibly sensitive user-provided content are sent to an external service. In a content-generation skill this external transmission is expected, but it remains security-relevant because users are not warned about data egress, third-party processing, retention, or billing implications.

Content

Scanner excerpt · README.md (reported line 31)May include surrounding context.

bash
# 生成视频
curl -X POST "https://ark.cn-beijing.volces.com/api/v3/contents/generations/tasks" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer ${API_KEY}" \
  -d '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly demonstrates authenticated requests to a third-party API and identifies a local credential file, but provides no warning that prompts and related content will be transmitted externally or that the credential file is sensitive. This can cause users or downstream agents to send private data off-host or mishandle API secrets without understanding the security implications.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 65)May include surrounding context.

md
## 详细文档

查看完整文档:`~/.openclaw/skills/jimeng-video/SKILL.md`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly instructs users to send prompts and media-generation requests to a third-party API, but it does not clearly warn that user-provided prompts and possibly image inputs will leave the local environment and be processed by an external provider. This creates a real data-handling risk if users include sensitive business data, personal data, or proprietary media under the assumption the skill operates locally.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The documented curl example shows direct transmission of generation content to an external endpoint using an API key, confirming that user inputs are sent off-platform. While external API use is expected for this type of skill, the lack of explicit consent and safety guidance makes it risky because users may unknowingly transmit confidential prompts or media to a third party.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

生成带声音的视频

bash
curl -X POST "https://ark.cn-beijing.volces.com/api/v3/contents/generations/tasks" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer ${API_KEY}" \
  -d '{

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This trigger is highly generic and likely to overlap with ordinary requests for AI video generation across many contexts. That increases the risk of accidental invocation of this skill over a more appropriate tool, which can expose user content to third-party APIs and consume metered external services using stored secrets.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrase at this line is broad enough to match many general user requests for video creation, not just requests specifically intended for this skill. In an agent ecosystem, overly generic triggers can cause unintended skill invocation, leading to surprise execution, unnecessary use of configured API credentials, and possible routing of user prompts to an external provider without clear user intent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.