Back to skill

Security audit

AI短视频工厂

Security checks for vulnerabilities and agentic risk

Overview

This is a Markdown-only short-video production workflow with some broad triggers and external media-service use, but no hidden code, persistence, credential use, or destructive behavior.

Before installing, be aware that using this skill may involve processing links, uploaded media, and generated assets through external stock-media or AI services. Avoid confidential or proprietary materials unless you have reviewed the tools being used, and verify copyright and platform-compliance claims before publishing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger list includes highly generic phrases such as '做视频', '生成视频', and 'video production', which can match ordinary user requests unrelated to this specialized skill. Overbroad activation can cause unintended invocation, exposing user prompts, links, or uploaded media to this workflow and any connected external services without clear user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The keyword tables remain broad even after exclusions because many entries are category-level terms rather than precise commands, increasing the chance of accidental triggering. In this skill, unintended activation matters because the workflow explicitly accepts URLs, competitor video links, and uploaded assets that may then be processed or analyzed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill solicits URLs, competitor links, and user-uploaded materials, and later references external asset sources and AI generation services, but it does not clearly warn users that these inputs may be transmitted to third parties for analysis or processing. This undermines informed consent and can lead to inadvertent disclosure of sensitive or proprietary media, campaign plans, or unpublished content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The line “中文输出” imposes a fixed output language, while the rest of the skill supports multiple languages and does not state that Chinese-only output is required for compliance or region-specific use. This is a natural-language policy issue because it removes user language choice without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Line L047 states '需英文字幕或双语字幕' as a blanket requirement. This is a natural-language locale policy constraint that forces a specific language output without user opt-in or clarification that the workflow is limited to an English-speaking or international audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.