Back to skill

Security audit

seko video creation - All-in-one AI video creation by seko.sensetime.com

Security checks for vulnerabilities and agentic risk

Overview

This Seko video-creation skill mostly matches its stated purpose, but it tells the agent to save the user's API key in a local .env file without adequate safeguards.

Review this before installing if you will use a real Seko API key. Prefer setting SEKO_API_KEY only in your shell or a managed secret store, and avoid letting the skill write it to a project .env file unless you understand the exposure risk and protect or delete that file afterward.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:61
Finding

Plaintext Persistence of the Seko API Key

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 61–64
Vulnerability Type: Plaintext sensitive-data storage
Risk Level: Medium

Vulnerable Instruction

text
### Step 2
Set the SEKO_API_KEY environment variable.
Check whether the current environment variables include SEKO_API_KEY.
If it is not set, explicitly ask the user to provide SEKO_API_KEY and tell the user that it can be obtained from https://seko.sensetime.com/explore.
If SEKO_API_KEY is obtained, save it to .env. Then set the environment variable from .env and verify that it is correctly configured.

The snippet above is an English translation of the original instruction at the cited location.

Technical Analysis

The Skill explicitly directs the Agent to persist the user's Seko API credential in a .env file. It does not specify:

  • A protected storage location outside the project workspace
  • Owner-only file permissions
  • User consent for persistent credential storage
  • Exclusion from version control
  • Secret-manager integration
  • Credential expiration, rotation, or cleanup

Although using the API key to authenticate to the declared Seko service is necessary for the Skill's functionality, persistent plaintext storage is not required. The scripts already support reading SEKO_API_KEY directly from the process environment, so the .env persistence instruction exceeds the minimum storage privilege needed for authenticated API calls.

Attack Path

  1. The user supplies a valid SEKO_API_KEY.
  2. Following SKILL.md, the Agent writes the credential into {PROJECT_DIR}/.env.
  3. The project directory is committed to version control, archived, backed up, shared with another party, or read by another local process or user.
  4. The unauthorized party retrieves the plaintext credential.
  5. The exposed key is reused against the Seko API until it is revoked or expires.

This path does not require code execution within ...[truncated 652 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the instruction to save SEKO_API_KEY to {PROJECT_DIR}/.env.
  2. Read the credential from the existing process environment, which all authenticated scripts already support.
  3. When persistence is necessary, require explicit informed user consent and use an operating-system credential store or managed secret service.
  4. If a .env file must be supported:
    • Store it outside shared project content.
    • Create it with owner-only permissions, such as mode 0600 on POSIX systems.
    • Add .env to .gitignore before creating the file.
    • Never print or include its value in logs, command examples, task records, or error messages.
    • Delete it when the workflow finishes unless the user explicitly requests retention.
  5. Prefer short-lived, least-privileged API credentials and document revocation and rotation procedures.
  6. Continue sending the key only to the fixed HTTPS Seko API host; validate the configured hostname against an allowlist before attaching the authentication header.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear mismatch between the declared description and the actual code. The description promises a full AI filmmaking/video generation pipeline, but the code only implements image/file downloading from a URL to local storage. The only substantive capability present is network retrieval and filesystem writing, which is unrelated to the claimed end-to-end AI video creation workflow. This is a materially different primary purpose, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a full-featured AI filmmaking and video-generation platform. In contrast, the actual code only accepts a URL and output path, then downloads the remote content to a local file. There is no evidence of text-prompt-based generation, script creation, character or scene design, storyboard creation, lip-sync, subtitle generation, music creation, transitions, or any broader production workflow. The primary behavior is materially different: remote file retrieval rather than AI video creation. Therefore, the description does not accurately represent the code's behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description promises a comprehensive AI video creation solution covering the entire filmmaking pipeline and multiple media-processing capabilities. The supplied code does not implement those capabilities; it only sends a prompt to a remote Seko API planning endpoint and outputs the response. While the remote service might ultimately support broader video-generation features, this specific code chunk demonstrates only proposal/plan task submission. That is a materially narrower and different behavior than the declared all-in-one video production functionality. Additionally, the code uses network access and local configuration/API key retrieval despite no declared permissions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description promises a comprehensive AI video creation capability covering the entire filmmaking pipeline. However, this code chunk does not perform content generation or video creation. Its concrete behavior is limited to: loading config, calling a Seko API status endpoint for a plan task, optionally polling until the task completes, writing the API response to a JSON file, and downloading element images referenced in the response. That is a materially narrower and different purpose than the declared all-in-one video creation functionality. While this script may support a larger system, this specific code does not match the declared primary capability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a comprehensive AI video creation product that transforms a simple prompt into a full production-ready video across the entire filmmaking pipeline. The supplied code does not implement that behavior. Instead, it only queries a remote API for the status of an already-created task, optionally waits for completion, writes the returned JSON to disk, and downloads the resulting video from storyWorksUrl when available. While this may be one supporting component of a larger video-generation system, the code chunk itself is materially narrower and has a different primary purpose: task-status retrieval and asset download, not all-in-one video creation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description promises a comprehensive AI video creation system covering end-to-end filmmaking functions. The actual code chunk only implements a command-line request to modify an existing task/proposal using a prompt and task ID against a Seko API endpoint. While this may be one internal helper within a larger system, based on the provided code alone the observed behavior is limited to plan-task modification, not video creation. Therefore the declared purpose does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The skill explicitly requests a sensitive API credential from the user and directs that it be saved into a .env file, creating a credential-handling risk. In this context, the danger is amplified because the workspace is also used for file operations and project artifact generation, so the secret may remain accessible longer than necessary and be exposed to other processes or future tasks.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

md
设置 SEKO_API_KEY 环境变量。
检查当前环境变量是否包括 SEKO_API_KEY ,
如果没有设定,明确向用户要求提供这个 SEKO_API_KEY,提示用户可在 https://seko.sensetime.com/explore 获取 SEKO_API_KEY,
如果获得了SEKO_API_KEY,保存到 .env 中。并根据 .env 设置环境变量,检查以确保这个环境变量必须被正确设置。

### 任务1: 影视策划
#### 第一步

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/gen_proposal.py (reported line 20)May include surrounding context.

python
onfig():
    """
    加载配置文件
    """
    config_path = os.path.join(os.path.dirname(__file__), "../assets/config.json")
    try:
        with open(config_path, "r", encoding="utf-8") as f:
            return json.load(f)
    except Exception as e:
        print(f"Warning: Failed to load config from {config_path}: {e}")
        return {}

def main():
    parser = argparse.ArgumentParser(description='Generate a proposal via Seko API.')
    parser.add_argument('--prompt', type=str, required=True, help='The prompt to send to the API')
    parser.add_argument('--seko_api_key', type=str, help='The Seko API key (optional)')

    args = parser.parse_args()

    # Determine API key
    api_key = args.seko_api_key
    if not api_key:
        api_key = os.environ.get('SEKO_API_KEY')
    
    if not api_key:
        print("Error: Seko-API-Key not found. Please provide it via --seko_api_key or as an environment variable.", file=sys.stderr)
        sys.exit(1)

    # Load config
    confi

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill instructs the agent to read environment variables, write files, and perform outbound network operations, but it does not declare any corresponding tool scope such as permissions or allowed-tools. This weakens least-privilege controls and makes the skill's effective capability surface broader and less auditable than its manifest suggests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction '必须使用中文进行回答/编写' forces a specific language for all interactions. This is a natural-language policy issue because it removes user language choice and provides no opt-in mechanism or region-specific justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs storing the user's SEKO API key in a local .env file without warning, consent, retention limits, or protection guidance. Persisting credentials to disk increases the chance of accidental exposure through workspace sharing, logs, backups, or later file reads by other tools or skills.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sends the user-supplied prompt to a remote Seko API endpoint, but it provides no user-facing disclosure at the time of transmission beyond generic CLI argument help. In an agent-skill context, prompts may contain sensitive business, personal, or proprietary data, so undisclosed exfiltration to a third-party service creates a real privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code prepares and sends an HTTPS POST request containing the user-supplied modification instruction and task identifier to an external service. Although the network call is visible in code, there is no confirmation prompt or explicit disclosure message informing the user that their input and task metadata will be transmitted off-host.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The code includes Chinese-only natural-language content in the docstring/commentary, which indicates a language assumption without any opt-in or explanation of a locale-specific requirement. Under the policy, language constraints should be optional or clearly justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest describes an AI video creation capability, and this file is documented as checking proposal task status. Reading credentials from process environment is an additional capability not mentioned in the manifest or this file's description, and is not inherently part of status retrieval logic itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file includes natural-language text in Chinese in the docstring/commentary, while the rest of the interface is in English, and there is no indication that the skill is intentionally region-specific or that language choice is user-selectable. This can violate language/locale policy when a specific language is imposed without opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.