Back to skill

Security audit

zxcvbnm-mnbvcxz

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent AIVideoMaker API helper; it uses an API key to send user-requested prompts and images to the service, with the main caution being normal external media handling and unclear upstream retention.

Install only if you intend to use AIVideoMaker with your API key. Avoid submitting sensitive, private, or proprietary images/prompts unless you are comfortable with AIVideoMaker processing them and potentially storing task inputs or uploaded image URLs; monitor credit usage and keep the API key in environment/secret storage.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill performs network-capable actions but does not declare an explicit tool scope such as permissions or allowed-tools. That creates a governance gap: callers or reviewers cannot reliably enforce or audit that the skill is only intended to use network access, increasing the chance of over-broad execution in permissive runtimes.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
- Validates input payloads against a defined contract
- Reads only payload passed via `--payload`
- Does not read arbitrary host files, credentials, or sensitive system information
- Does not execute arbitrary code or shell commands

All network requests are made to `https://aivideomaker.ai` (or an optional custom base URL configured via client options) and include only the API key for authentication.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest declares only "en" in the language field, which imposes a specific language/locale constraint. Under the policy rule, forcing a single language without user opt-in or a clear documented regional justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation states that base64 image inputs are uploaded to R2 and that task inputs later expose an R2 URL, but it does not clearly warn users that submitted image content is being persisted externally and may remain retrievable through task-detail endpoints. In a media-generation skill, users may reasonably assume transient processing; undocumented persistence increases privacy and data-handling risk, especially for sensitive or proprietary images.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The examples document a GET /api/v1/tasks task-listing capability that is outside the manifest’s stated scope of generation, status checks, details retrieval, and cancellation. This kind of scope drift is dangerous because agents or downstream users may infer and invoke undocumented data-access functionality, potentially exposing metadata or prompts for unrelated tasks if authorization boundaries are weak or misunderstood.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code accepts arbitrary HTTP/HTTPS image URLs as input, which implies a network fetch or transmission path for user-supplied data. In this file there is no confirmation, logging, comment, or docstring warning users that external image URLs may be retrieved or transmitted.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/aivideo-client.mjs:5