Back to skill

Security audit

Tencent Hy-MT2-Translator

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real translation tool, but it persistently stores API keys and can send both credentials and translated content to user-configured endpoints, so it needs careful review before installation.

Install only if you are comfortable storing translation API credentials in agent memory and sending source text, files, terminology, and context to the selected remote endpoint. Prefer a private backend you control, avoid entering highly sensitive documents, do not override the Tencent URL unless you fully trust the destination, rotate any API key used with this skill, and delete any remembered credentials/backend settings when no longer needed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/hy_translate.py:153
Finding

Arbitrary API endpoints receive credentials and complete translation content

Content
View full analysis
str: """Call translation API via OpenAI-compatible interface.""" cfg = API_BACKENDS[backend] url = url or cfg["url"] model = model or cfg["default_model"] if not url: raise ValueError( f"No endpoint URL provided for backend '{backend}'. " f"Pass --url on the command line." ) headers = { "Content-Type": "application/json", "Authorization": f"Bearer {api_key}", } payload = { "model": model, "messages": [{"role": "user", "content": prompt}], "temperature": 0.1, "max_tokens": 4096, "stream": False, } for attempt in range(MAX_RETRIES): try: resp = requests.post(url, headers=headers, json=payload, timeout=REQUEST_TIMEOUT) ``` The associated Skill instructions explicitly permit a custom Tencent Cloud URL and persistence of that URL: ```markdown - **`tencent_cloud`**: Uses the Hy Translation API provided by Tencent Cloud. The endpoint URL has a built-in default (`https://api.hunyuan.cloud.tencent.com/v1/chat/completions`) — the user does not need to provide it. However, the user may optionally supply a different URL, which will be stored in memory and used going forward. ``` ### Technical Analysis The script sends both the Bearer API key and the complete translation prompt to the value supplied through `--url`. No validation requires HTTPS, verifies the expected hostname, constrains Tencent credentials to the official Tencent endpoint, or warns when the endpoint changes. This network behavior is necessary ...[truncated 1682 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:67
Finding

API keys are persistently stored and exposed through command-line arguments

Content
View full analysis
" \ --target-lang "" \ --backend \ --url "" \ --model "" \ --api-key "" ``` The implementation requires and reads the command-line value: ```python parser.add_argument("--api-key", required=True, help="API key") ``` ```python # Resolve API key api_key = args.api_key ``` ### Technical Analysis The Skill requires API keys to be stored in persistent agent memory without defining encryption, access controls, retention limits, deletion procedures, or backend isolation. It then instructs the agent to insert those credentials into command-line arguments. Command-line secrets may be visible in process listings while the ...[truncated 1365 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:190
Finding

Predictable shared temporary file can disclose data or enable symlink attacks

Content
View full analysis
/tmp/hy_src.txt << 'EOF' EOF python3 "$HY_SCRIPT" \ --input-file /tmp/hy_src.txt \ --target-lang "" \ --backend \ --url "" \ --model "" \ --api-key "" ``` ### Technical Analysis The workflow writes source text to a fixed path in a shared temporary directory. It does not use exclusive creation, a randomized filename, restrictive permissions, or guaranteed cleanup. On systems where another local user can create entries in `/tmp`, an attacker can pre-create `/tmp/hy_src.txt` as a symbolic link. The shell redirection follows the link and truncates or overwrites the referenced file with the privileges of the process running the Skill. The practical overwrite scope depends on the invoking account's permissions. Even without a symlink attack, sensitive source text can remain at a predictable location after translation. The default process umask may also produce permissions that permit unintended local access. ### Attack Path 1. A local attacker anticipates use of the documented multiline translation workflow. 2. The attacker creates `/tmp/hy_src.txt` as a symbolic link to a file writable by the Skill's operating-system account, or monitors the predictable path. 3. The agent executes `cat > /tmp/hy_src.txt`. 4. Shell redirection follows the symbolic link and truncates or overwrites the target, or creates a predictable file containing sensitive text. 5. The attacker reads the source data if permissions allow, or causes corruption of another file writable by the invoking account. 6. Because no cleanup is specified, the data may remain accessible after the translation completes. ### Impact Assessment Potential impact inc ...[truncated 277 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (20)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to persist backend URLs, model identifiers, and API keys across sessions, creating long-lived credential storage unrelated to the core act of translation. Persistent secrets increase the blast radius of memory leakage, cross-session misuse, unauthorized backend switching, and accidental reuse without fresh user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill tells the agent to store API keys and backend settings in memory across sessions without a user-facing warning or explicit consent flow. That creates hidden persistence of secrets and infrastructure details, making accidental retention and later reuse likely and increasing exposure if memory is accessed by other tasks or compromised components.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill requires filesystem reads/writes and network access but declares no explicit tool scope or permissions boundaries. This increases the chance an agent will run the skill with broader capabilities than necessary, making misuse or accidental overreach harder to constrain and audit.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill mandates use for all translation requests without exception, encouraging blanket invocation regardless of data sensitivity, environment, or safer alternatives. Over-broad invocation guidance can route confidential content to external services or trigger file/network operations in contexts where the user did not explicitly consent.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
81% confidence
Finding

The instruction to reuse a previously selected backend from memory and 'do not ask the user again' delegates potentially sensitive routing decisions to autonomous state rather than fresh user confirmation. In context, that can silently send new translation content to a previously chosen external or custom endpoint, including one persisted across sessions.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

md
1. **Check conversation history and memory** for the most recently used backend:
   - Look at recent messages in the current conversation first.
   - If not found in conversation, check memory key `active_translation_backend`.
   - If found, use that backend — **do not ask the user again**.

2. **If no prior backend is found** in history or memory:
   - Ask the user which backend to use: Tencent Cloud or Private Model.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instruction to run find ~ causes broad discovery across the user's home directory to locate a script, which exceeds what is necessary for a translation skill. Home-directory enumeration can expose unrelated files, reveal sensitive path structures, and normalize overly broad file access for a routine task.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs writing source text to /tmp and processing input/output files without warning that content may persist locally or be accessible to other local processes depending on system configuration. For translation tasks involving sensitive text, temporary-file handling can lead to unintended data residue and broader disclosure than the user expects.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The style-mode trigger is defined as matching any style adjective, which is overly broad and can cause ordinary user text to be reinterpreted as a control signal rather than content. In a translation skill, this can let untrusted input unexpectedly switch prompting behavior, increasing the chance of prompt confusion, instruction injection into the style field, or incorrect translations when benign descriptive text is misclassified as a mode selector.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
hy_translate.py - Hy Translation Skill script

Supports two API backends via OpenAI-compatible interface:
  - tencent_cloud : Tencent Cloud Hy  (https://api.hunyuan.cloud.tencent.com/v1/chat/completions)
  - private_model : Self-hosted private model service (pass --url and --model at runtime)

Usage examples:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
hy_translate.py - Hy Translation Skill script

Supports two API backends via OpenAI-compatible interface:
  - tencent_cloud : Tencent Cloud Hy  (https://api.hunyuan.cloud.tencent.com/v1/chat/completions)
  - private_model : Self-hosted private model service (pass --url and --model at runtime)

Usage examples:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

md
hy_translate.py - Hy Translation Skill script

Supports two API backends via OpenAI-compatible interface:
  - tencent_cloud : Tencent Cloud Hy  (https://api.hunyuan.cloud.tencent.com/v1/chat/completions)
  - private_model : Self-hosted private model service (pass --url and --model at runtime)

Usage examples:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
hy_translate.py - Hy Translation Skill script

Supports two API backends via OpenAI-compatible interface:
  - tencent_cloud : Tencent Cloud Hy  (https://api.hunyuan.cloud.tencent.com/v1/chat/completions)
  - private_model : Self-hosted private model service (pass --url and --model at runtime)

Usage examples:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/hy_translate.py (reported line 7)May include surrounding context.

python
hy_translate.py - Hy Translation Skill script

Supports two API backends via OpenAI-compatible interface:
  - tencent_cloud : Tencent Cloud Hy  (https://api.hunyuan.cloud.tencent.com/v1/chat/completions)
  - private_model : Self-hosted private model service (pass --url and --model at runtime)

Usage examples:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/hy_translate.py (reported line 72)May include surrounding context.

python
hy_translate.py - Hy Translation Skill script

Supports two API backends via OpenAI-compatible interface:
  - tencent_cloud : Tencent Cloud Hy  (https://api.hunyuan.cloud.tencent.com/v1/chat/completions)
  - private_model : Self-hosted private model service (pass --url and --model at runtime)

Usage examples:

Ssd 1

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

User-controlled terminology is inserted verbatim into the prompt as trusted guidance, so an attacker can smuggle behavioral instructions such as output manipulation, prompt leakage attempts, or policy bypasses disguised as term mappings. Because the model receives these instructions in the same trust context as the translation directive, this can alter output semantics or cause the model to ignore intended constraints.

Content

No source excerpt is available for this finding.

Ssd 1

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The style parameter is interpolated directly into the prompt and can be abused to carry instruction-like text framed as style requirements, potentially changing model behavior beyond tone. In this skill context, style is expected to be user-controlled, which makes the issue less suspicious but still a real prompt-injection surface that can weaken translation-only guarantees.

Content

No source excerpt is available for this finding.

Ssd 1

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Free-form context is presented as trusted background information and can include adversarial instructions that override or distort the translation task. Since context-aware translation is a core feature, the dangerous part is not its existence but the lack of separation between user data and control instructions, enabling semantic prompt injection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sends user-provided text, file contents, and batch JSONL records to external endpoints for translation without any explicit consent prompt, sensitivity check, or redaction safeguard. In a translation skill, this is especially relevant because users may pass confidential documents, structured data, or proprietary text assuming local processing, creating a real data disclosure risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This call performs the actual external transmission of prompts and therefore of the user's source text and auxiliary metadata to a remote service. In a translation tool this is functionally necessary, but it still represents a genuine security/privacy concern because sensitive content leaves the local environment and may also be sent to user-specified private endpoints.

Content

Scanner excerpt · scripts/hy_translate.py (reported line 189)May include surrounding context.

python
for attempt in range(MAX_RETRIES):
        try:
            resp = requests.post(url, headers=headers, json=payload, timeout=REQUEST_TIMEOUT)
            if resp.status_code == 200:
                data = resp.json()
                msg = data["choices"][0]["message"]

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE_Hy-MT2-Translator.txt (reported line 12)May include surrounding context.

text
--------------------------------------------------------------------
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Static analysis

No suspicious patterns detected.