Back to skill

Security audit

Api Consumption Optimizer

Security checks for vulnerabilities and agentic risk

Overview

This skill is not clearly malicious, but it encourages unbounded automated API consumption that could exhaust quota or create billing and service-use risk.

Review this carefully before installing. It appears intended to help consume MiniMax API quota efficiently, but its examples encourage continuous automated calls without built-in limits. Only use it where you control the account, understand billing/quota consequences, and add explicit maximum calls, runtime limits, cancellation controls, and service-policy checks.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

该技能的触发场景仅写为“需要智能消耗 API 调用次数时”“需要根据剩余次数和时间动态调整调用频率时”,属于高层意图描述,缺少具体触发短语、适用上下文或排除条件。这种表述容易与常见的 API 优化/限流讨论重叠,导致技能被意外调用。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example shows an unbounded while True loop that continuously sleeps and performs API calls, effectively automating resource consumption without an explicit stop condition, quota ceiling, or operator confirmation. In context, the stated purpose is to maximize API quota usage, so omission of warnings and safeguards makes accidental overconsumption, billing impact, or service abuse materially more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The integration example continuously queries status from an external system and invokes do_game_ai_call() in a perpetual loop, again without risk disclosure, stop conditions, or misuse constraints. Because the skill is explicitly designed to maximize consumption before reset, this context makes the automation more dangerous: it encourages sustained external API activity that could exhaust quotas, incur charges, or violate platform usage expectations.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · api_consumption_optimizer.py (reported line 18)May include surrounding context.

python
def get_minimax_status():
    """获取 MiniMax 当前状态"""
    try:
        result = subprocess.run(
            ['/home/garfield/.local/bin/minimax-status-clean'],
            capture_output=True,
            text=True,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

整个技能说明仅以中文呈现,未说明语言要求、适用用户范围或是否支持其他语言/本地化选项。若组织要求避免在无用户选择的情况下强制特定语言,这种单一语言呈现可能构成自然语言政策问题。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The top-level documentation says the skill will 'dynamically adjust consumption strategy,' which implies it actively influences API usage. In practice, the file only invokes a local status command, parses output, and returns calculated recommendations such as interval_seconds; it does not schedule, throttle, or modify API calls itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module title, docstrings, and all user-facing status strings are written in Chinese, including the printed summary and error messages. For a general-purpose optimizer, this imposes a specific language on users without opt-in or any documented region-specific justification, which matches the locale-policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.