Back to skill

Security audit

WorkRally 视频生成(SkillPay)

Security checks for vulnerabilities and agentic risk

Overview

This is a paid WorkRally video-generation skill with clear payment flow and expected cloud processing, with privacy and locale considerations users should understand.

Before installing, users should be comfortable with a 6.88 RMB charge per generation through WeChat Pay and with any supplied reference image being sent to WorkRally's cloud service for processing. Avoid using sensitive images unless that transfer is acceptable, and save generated result links promptly because they are documented as short-lived.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README clearly states this is a paid skill and describes a per-generation payment authorization flow, but it does not explicitly require the agent to present a clear user-facing charge warning and obtain informed confirmation before initiating payment. In an agent ecosystem, this can lead to accidental or opaque charges, especially when the workflow is automated and the user may not realize that invoking generation immediately enters a billable authorization flow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs the agent to send a local image as an inline base64 payload to a remote cloud API, but it does not warn that this transfers user-provided local content off-device to a third party. That creates a real privacy and consent risk, especially if users upload sensitive photos, documents, or proprietary images under the assumption they remain local.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all user-facing instructions and pricing details exclusively in Chinese. The policy requires flagging language or locale constraints when a specific language is effectively forced without user opt-in or a documented regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Line L49 instructs that the character speaks in '普通话' (Mandarin Chinese) as part of the default example, which can be read as prescribing a specific language output. The file does not state that language should be selected based on user preference or that the skill is intentionally limited to a Chinese-language context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains natural-language instructions that require users to complete 微信支付 authorization before proceeding. That is a locale/payment-channel specific constraint, and the file does not indicate user choice, opt-in, or a documented regional justification for forcing this path.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The natural-language content of the skill appears to require Chinese for understanding and use, but it does not state that the skill is Chinese-only by design or offer an alternate language option. Per the policy, forcing a specific language without user opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

All instructional text and user-facing example prompts in this file are presented only in Chinese, which can amount to a language/locale constraint without opt-in. The file does not state that the skill is intentionally limited to a Chinese-speaking or region-specific context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.