Back to skill

Security audit

HotBee 音视频转文字

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent transcription purpose, but it tells agents to execute mutable GitHub-hosted code with an API key and sends sensitive values as URL query parameters.

Review before installing. Use only media you are allowed to submit, prefer non-sensitive or short-lived media URLs, and avoid exposing broad environment secrets to the CLI. The publisher should replace the GitHub `npx` tag with an immutable reviewed package or commit and move secrets/media URLs out of query parameters.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:14
Finding

Runtime Retrieval and Execution of a Mutable GitHub Dependency

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/api.md:5
Finding

API Key and Sensitive Media URLs Transmitted in Query Parameters

Content
View full analysis
Remediation
View remediation
`, rather than in the query string. 2. Send `file_url` or `video_url` in the POST request body using JSON or another appropriate content type. 3. Configure all clients, servers, proxies, gateways, and monitoring systems to redact authorization values, media URLs, and sensitive query parameters. 4. Ensure errors do not reproduce complete request URLs or signed media parameters. 5. Verify and document the ownership and trust relationship of the `smsz.xyz` endpoint before sending credentials or private media URLs. 6. Use narrowly scoped, revocable API credentials and rotate the current credential if it may already have appeared in logs. 7. Prefer short-lived media URLs with the minimum necessary permissions and expiration period. 8. Obtain explicit user confirmation before transmitting private media to the third-party service, including a clear statement that the media URL will leave the local environment. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The skill instructs users to execute code directly from a GitHub repository via npx -y github:...#v1.1.0, which is a remote code execution path and not a securely pinned package artifact. Although a tag is present, Git tags can be moved and GitHub-sourced installs bypass the stronger integrity guarantees of registry-published packages with lockfile or digest verification, creating a supply-chain risk. In this skill context, the command is especially sensitive because it processes external media URLs and is expected to access HOTBEE_API_KEY from the local environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The documentation instructs users to run npx -y github:...#v1.1.0, which fetches and executes code directly from a GitHub repository rather than a registry package with stronger provenance controls. Even though a tag is specified, tags can be moved or the referenced repository can be compromised, so this creates a supply-chain risk where users may execute unexpected code.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.