Back to skill

Security audit

550W AI去字幕去水印

Security checks for vulnerabilities and agentic risk

Overview

This skill sends user-selected media and account requests to the 550W service for watermark/subtitle removal, with the sensitive behaviors disclosed and gated by confirmations.

Install only if you are comfortable sending selected images, videos, share links, and 550W account credentials to the 550W service. Prefer OAuth where available; if using API keys, understand that the skill can store them locally in plaintext JSON with restricted file permissions. Confirm paid processing and task deletion carefully, especially because repeated submissions can spend credits and deleted tasks do not refund credits.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
Findings (57)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description focuses on media processing capabilities: removing subtitles, text, and watermarks from images/videos and handling social-media share links. The supplied code chunk does not implement any subtitle/watermark removal or link processing. Instead, it performs a destructive administrative action: deleting an existing task via an API endpoint, with confirmation gating and messaging about asynchronous media cleanup and no credit refund. This is a materially different capability that is not represented in the declared description, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This code chunk's primary function is account/usage management, not media processing. It posts to a credits endpoint, returns user number and credits, and optionally computes an estimated credit cost. None of the declared core behaviors—removing subtitles, removing watermarks, processing images/videos, or handling social-media share links—are implemented here. This is a material description-to-behavior mismatch rather than a mere supporting detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description focuses on media processing capabilities: removing subtitles, text, and watermarks from images/videos and handling social-media share links. The supplied code does not perform any media processing, watermark removal, subtitle removal, or link extraction. Instead, it queries a remote task list endpoint and returns paginated task records after removing some internal fields. This is a materially different primary purpose from the declared functionality, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared purpose emphasizes media processing capabilities: removing text/watermarks from images, hard subtitles and visual watermarks from local videos, and handling social-media share links. However, this code chunk only implements a video upload action. It sends a file to a remote endpoint and returns upload results and metadata. There is no evidence here of subtitle removal, watermark removal, image processing, or social-link handling. Uploading may be a supporting step in a larger workflow, but taken on its own, this chunk's behavior is materially different from the declared end-user functionality and includes an undeclared remote upload capability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This code chunk’s primary function is secure local media upload preparation and transmission, not media transformation. It validates region/media type/path/ticket/URL, checks local file extension and size, opens and reads local files, then posts them to https://www.550wai.cn/mcp-media/... with an upload ticket. The declared description emphasizes AI subtitle/watermark removal for images/videos and handling share links from platforms like Douyin/Kuaishou/Bilibili/Weibo. None of that behavior appears in this code: there is no image/video processing, no OCR/inpainting/removal logic, no parsing of shared links, and no OAuth/API-key flow beyond a note that upload itself does not need OAuth. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description centers on AI-based removal of subtitles and watermarks from images/videos and handling social-media share links. In contrast, this code chunk only implements a command-line interface for two operations: inspecting a local media file and uploading prepared media. There is no evidence in this chunk of image/video editing, OCR/inpainting, subtitle removal, watermark removal, or parsing/downloading social-media share links. While OAuth support is mentioned in the description and the code does relate to OAuth uploading, that is only a partial overlap and not the primary described function. Therefore, the code behavior materially differs from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a media-processing skill focused on removing subtitles and watermarks from images/videos and handling share links. However, the supplied code chunk only performs safe remote video URL validation and metadata extraction using ffprobe. This is a materially different function from the declared end-user purpose. While such probing could be a supporting step in a larger video-processing pipeline, this chunk by itself demonstrates an undeclared network inspection/probing capability and lacks any implementation of the advertised removal features.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
但需要宿主允许读取用户指定文件并执行 Node.js,或支持相应文件传输。API Key 使用绝对 `params.filePath`;OAuth 使用随包 `scripts/550w-upload.cjs` 的 inspect/upload 与远程上传票据。读取对应流程后执行;不要在命令行、日志或公开包中放凭据。没有

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · dist/550w-mcp.cjs (reported line 736)May include surrounding context.

js
get error() {
            if (this._error)
              return this._error;
            const error = new ZodError_js_1.ZodError(ctx.common.issues);
            this._error = error;
            return this._error;
          }
        };
      }
    };
    function processCreateParams(params) {
      if (!params)
        return {};
      const { errorMap, invalid_type_error, required_error, description: description2 } = params;
      if (errorMap && (invalid_type_error || required_error)) {
        throw new Error(`Can't use "invalid_type_error" or "required_error" in conjunction with custom error map.`);
      }
      if (errorMap)
        return { errorMap, description: description2 };
      const customMap = (iss, ctx) => {
        const { message } = params;
        if (iss.code === "invalid_enum_value") {
          return { message: message ?? ctx.defaultError };
        }
        if (typeof ctx.data === "undefined") {
          return { message: message ?? required_error ??

YARA rule 'exploit_framework': Exploit framework components and payloads [hacktools]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · dist/550w-mcp.cjs (reported line 24671)May include surrounding context.

js
...util.normalizeParams(params)
      });
    }
    // @__NO_SIDE_EFFECTS__
    function keyof(schema) {
      const shape = schema._zod.def.shape;
      return /* @__PURE__ */ _enum(Object.keys(shape));
    }
    exports2.ZodMiniObject = core.$constructor("ZodMiniObject", (inst, def) => {
      core.$ZodObject.init(inst, def);
      exports2.ZodMiniType.init(inst, def);
      util.installLazyProp(inst, "shape", (self) => self._zod.def.shape, false);
    });
    // @__NO_SIDE_EFFECTS__
    function object(shape, params) {
      const def = {
        type: "object",
        shape: shape ?? {},
        ...util.normalizeParams(params)
      };
      return new exports2.ZodMiniObject(def);
    }
    // @__NO_SIDE_EFFECTS__
    function strictObject(shape, params) {
      return new exports2.ZodMiniObject({
        type: "object",
        shape,
        catchall: /* @__PURE__ */ never(),
        ...util.normalizeParams(params)
      });
    }
    // @__NO_SIDE_EFFECTS__
    function loos

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · dist/550w-mcp.cjs (reported line 35892)May include surrounding context.

js
function validateAsync() {
        const ruleErrs = gen.let("ruleErrs", null);
        gen.try(() => assignValid((0, codegen_1._)`await `), (e) => gen.assign(valid, false).if((0, codegen_1._)`${e} instanceof ${it.ValidationError}`, () => gen.assign(ruleErrs, (0, codegen_1._)`${e}.errors`), () => gen.throw(e)));
        return ruleErrs;
      }
      function validateSync() {
        const validateErrs = (0, codegen_1._)`${validateRef}.errors`;

Credential Access

High
Category
Privilege Escalation
Confidence
87% confidence
Finding

The skill stores API credentials in a local JSON file under the user config directory, which is plaintext at rest and recoverable by any process or user with access to that profile. In an agent/plugin ecosystem, persisted secrets expand the blast radius of host compromise and can be reused to make billable or account-affecting API calls.

Content

Scanner excerpt · dist/550w-mcp.cjs (reported line 43555)May include surrounding context.

js
var CredentialManager = class {
      constructor(storagePath) {
        const configRoot = process.env.XDG_CONFIG_HOME?.trim() || (process.platform === "win32" ? process.env.APPDATA?.trim() : null) || path.join(os.homedir(), ".config");
        this.storagePath = storagePath ?? path.join(configRoot, "550w-ai", "credentials.json");
        this.legacyStoragePath = path.resolve(__dirname, "../.credentials.json");
      }
      get() {

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

The code also supports a legacy credential file path (../.credentials.json), increasing the number of locations where reusable secrets may persist and be discovered. Multiple storage paths complicate auditing and cleanup, and may leave stale credentials behind after migration.

Content

Scanner excerpt · dist/550w-mcp.cjs (reported line 43556)May include surrounding context.

js
constructor(storagePath) {
        const configRoot = process.env.XDG_CONFIG_HOME?.trim() || (process.platform === "win32" ? process.env.APPDATA?.trim() : null) || path.join(os.homedir(), ".config");
        this.storagePath = storagePath ?? path.join(configRoot, "550w-ai", "credentials.json");
        this.legacyStoragePath = path.resolve(__dirname, "../.credentials.json");
      }
      get() {
        const envUserNo = process.env.SUBTITLE_REMOVER_USER_NO?.trim();

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
const configRoot = process.env.XDG_CONFIG_HOME?.trim()
            || (process.platform === "win32" ? process.env.APPDATA?.trim() : null)
            || path.join(os.homedir(), ".config");
        this.storagePath = storagePath ?? path.join(configRoot, "550w-ai", "credentials.json");
        this.legacyStoragePath = path.resolve(__dirname, "../.credentials.json");
    }
    get() {

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · dist/550w-skill.cjs (reported line 260)May include surrounding context.

js
const configRoot = process.env.XDG_CONFIG_HOME?.trim()
            || (process.platform === "win32" ? process.env.APPDATA?.trim() : null)
            || path.join(os.homedir(), ".config");
        this.storagePath = storagePath ?? path.join(configRoot, "550w-ai", "credentials.json");
        this.legacyStoragePath = path.resolve(__dirname, "../.credentials.json");
    }
    get() {

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · dist/550w-skill.cjs (reported line 261)May include surrounding context.

js
const configRoot = process.env.XDG_CONFIG_HOME?.trim()
            || (process.platform === "win32" ? process.env.APPDATA?.trim() : null)
            || path.join(os.homedir(), ".config");
        this.storagePath = storagePath ?? path.join(configRoot, "550w-ai", "credentials.json");
        this.legacyStoragePath = path.resolve(__dirname, "../.credentials.json");
    }
    get() {

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · review/sources/dist/credential-manager.js (reported line 47)May include surrounding context.

js
const configRoot = process.env.XDG_CONFIG_HOME?.trim()
            || (process.platform === "win32" ? process.env.APPDATA?.trim() : null)
            || path.join(os.homedir(), ".config");
        this.storagePath = storagePath ?? path.join(configRoot, "550w-ai", "credentials.json");
        this.legacyStoragePath = path.resolve(__dirname, "../.credentials.json");
    }
    get() {

Credential Access

High
Category
Privilege Escalation
Confidence
76% confidence
Finding

The fallback to a legacy credential file inside the skill/package directory can expose secrets to a broader set of local users or processes than a normal per-user config location, depending on installation path and directory permissions. In shared environments or packaged distributions, storing or reading credentials from application directories increases the risk of accidental disclosure, backup leakage, or inclusion in artifacts.

Content

Scanner excerpt · review/sources/dist/credential-manager.js (reported line 48)May include surrounding context.

js
|| (process.platform === "win32" ? process.env.APPDATA?.trim() : null)
            || path.join(os.homedir(), ".config");
        this.storagePath = storagePath ?? path.join(configRoot, "550w-ai", "credentials.json");
        this.legacyStoragePath = path.resolve(__dirname, "../.credentials.json");
    }
    get() {
        // 优先从环境变量读取

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/550w-upload.cjs (reported line 8960)May include surrounding context.

js
if (!(key in state.jobs)) {
          return;
        }
        delete state.jobs[key];
        if (error) {
          abort(state);
        } else {

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises and documents capabilities that require environment access, network communication, and local execution, but it does not declare an explicit tool/permission scope. That creates a confused-deputy risk where hosts or reviewers may underestimate what the skill can do, especially since it can upload user media, use credentials, and invoke local binaries.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · dist/550w-mcp.cjs (reported line 30757)May include surrounding context.

js
* Controls when tools are used:
       * - "auto": Model decides whether to use tools (default)
       * - "required": Model MUST use at least one tool before completing
       * - "none": Model MUST NOT use any tools
       */
      mode: z.enum(["auto", "required", "none"]).optional()
    });

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code hard-codes the domestic package to return "zh" regardless of the user's locale, which is a language/locale policy choice applied automatically rather than by user selection. Because the file contains many user-facing localized messages, this behavior can force a specific language experience without explicit opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest focuses on media processing and support for OAuth MCP or API key access, but the implementation goes further by reading credentials from environment variables and storing them in local configuration files. Credential persistence is not an obvious implementation detail of subtitle/watermark removal itself and materially expands what the skill does.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

A subtitle/watermark remover would reasonably call a backend API, but implementing its own credential vaulting and file-based secret persistence is a separate account-management capability. That capability is not clearly justified by the stated purpose of removing subtitles and watermarks from media.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The locale resolver unconditionally returns "zh" whenever the packaged distribution region is "domestic", regardless of the user's requested locale or environment. This is a natural-language locale policy issue because the skill can force a specific language based on build region rather than explicit user choice.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution, suspicious.env_credential_access

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
dist/550w-mcp.cjs:36944

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
review/sources/node_modules/ajv/dist/compile/index.js:89

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/550w-mcp.cjs:43450