Back to skill

Security audit

AI Animation Studio

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed AI animation workflow with expected external media generation and local video processing, and I found no hidden persistence, deception, or malicious behavior.

Install only if you are comfortable using Doubao/ARK media generation, Edge TTS, and ffmpeg, and avoid submitting confidential stories, private images, personal dialogue, or unauthorized voice-like content. Expect Windows-specific local paths such as D:\AI视频资源 and a hardcoded doubao-media script path to need adjustment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · resource_index.py (reported line 133)May include surrounding context.

python
"prompt": row[1]
            })
    
    return prompts

def load_ai_prompts():
    """加载AI生图指令"""

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · resource_index.py (reported line 156)May include surrounding context.

python
"prompt": row[1]
            })
    
    return prompts

def load_ai_prompts():
    """加载AI生图指令"""

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are very broad, generic terms for common animation and video tasks, with no scoping rules or exclusions. That increases the chance of unintended activation in unrelated conversations, causing the skill to collect user inputs, route content into automation, or steer users into external media-generation workflows without clear intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly relies on a third-party remote API for image/video generation and references an API key, but it does not disclose that user prompts, images, and related media may be transmitted off-platform. This can mislead users about where their content goes and expose sensitive creative material or personal data to external processors without adequate notice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill promises automatic voice generation and subtitle processing but does not warn users that stories, dialogue, character details, or voice-like content may be sensitive. In practice, users may submit personal, confidential, or biometric-adjacent data to the workflow without informed consent, creating privacy and data-handling risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module title and description are written entirely in Chinese, and the rest of the user-facing strings and prompts in the file also assume Chinese usage. There is no indication that language selection is optional or that the skill is intentionally limited to a Chinese-only regional context, which can violate language/locale choice policy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

generate_image sends the supplied prompt to doubao_media.py via a subprocess, and the file provides no user disclosure in comments, docstrings, or warnings that prompts may be sent to an external media-generation service. Because prompts can contain sensitive user content, this network/data transmission behavior should be clearly disclosed.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · create_animation.py (reported line 57)May include surrounding context.

python
"--size", size
        ]
        
        result = subprocess.run(cmd, capture_output=True, text=True, encoding='utf-8')
        
        if result.returncode != 0:
            print(f"  [ERROR] 图片生成失败: {result.stderr[:100]}")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · create_animation.py (reported line 85)May include surrounding context.

python
"--size", size
        ]
        
        result = subprocess.run(cmd, capture_output=True, text=True, encoding='utf-8')
        
        if result.returncode != 0:
            print(f"  [ERROR] 图片生成失败: {result.stderr[:100]}")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

image_to_video passes the image URL and prompt to doubao_media.py, which likely causes remote processing or transmission of user content, but the file contains no disclosure of that behavior. Users are not warned that their image references and prompts may leave the local system during video generation.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · create_animation.py (reported line 170)May include surrounding context.

python
print(f"\n[BGM] 添加背景音乐: {os.path.basename(bgm_path)}")
        print(f"  音量: {int(bgm_volume*100)}%")
        
        result = subprocess.run(cmd, capture_output=True, text=True)
        
        if result.returncode == 0:
            print(f"  [OK] {output_path}")

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module title, description, docstrings, keys, and output messages are written exclusively in Chinese, indicating the skill is intended to operate in a single language with no opt-in or alternative locale support. Under the stated policy, forcing a specific language without user choice is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description forces a specific language/locale presentation in natural-language metadata, which can violate language-choice policy when no user opt-in or justification is provided. The same pattern is reflected across user-facing keywords and config labels, suggesting the skill is effectively Chinese-only by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The voice presets exclusively use zh-CN voices, which imposes a specific language/locale in the skill behavior. This matches the policy category for language or locale constraints when no user opt-in or alternative language selection is provided.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The select_bgm docstring explicitly describes a random selection mode via the random_select argument. However, the function calls random.choice at L111 and L115 without importing the random module anywhere in the file, so that advertised behavior will fail at runtime instead of working as documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The voice configuration specifies only zh-CN voices for all speakers, which enforces a specific language/locale in the skill content. Under the policy, locale restrictions should either be optional for the user or clearly documented as justified; this JSON provides no such opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.