Back to skill

Security audit

Tencent MPS

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Tencent MPS wrapper, but it needs Review because it explicitly supports anti-detection video deduplication and has risky dependency and credential handling.

Install only in an isolated virtual environment with least-privilege Tencent Cloud credentials. Avoid the video dedupe feature for platform-detection bypass, do not run the scripts from untrusted project directories, pin dependencies before use, and verify TENCENTCLOUD_MPS_ENDPOINT is one of Tencent's intended MPS endpoints.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T08 · Insecure Dependencies

Error
Location
scripts/mps_auto_upgrade.py:107
Finding

Automatic Runtime Installation of Unpinned Dependencies

Content
View full analysis
={min_ver_str}" if min_ver_str else pkg_name try: installed_ver = _pkg_version(pkg_name) except PackageNotFoundError: to_install.append(spec) continue if min_ver and _ver_tuple(installed_ver) < min_ver: to_install.append(spec) if to_install: _pip_install(to_install) for prefix in ("tencentcloud", "qcloud_cos", "dotenv"): for key in list(sys.modules.keys()): if key == prefix or key.startswith(prefix + "."): del sys.modules[key] ``` The dependency file only specifies minimum versions: ```text tencentcloud-sdk-python>=3.1.139 cos-python-sdk-v5>=1.9.30 python-dotenv>=1.0.0 ``` ### Technical Analysis Nearly every operational script calls `check_sdk_version()` before performing its primary function. If a dependency is mis ...[truncated 2030 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/mps_load_env.py:70
Finding

Overbroad Loading of Shell Profiles and Unrelated Environment Secrets

Content
View full analysis
dict: newly_loaded = {} seen_paths = set() def _load_and_collect(path_label, dotenv_path=None): before = dict(os.environ) try: ok = ( load_dotenv(dotenv_path=dotenv_path, override=False) if dotenv_path else load_dotenv(override=False) ) except (OSError, IOError) as e: if verbose: print(f"[load_env] Read failed: {path_label} ({e})", file=sys.stderr) return for key, value in os.environ.items(): if key not in before: newly_loaded[key] = value try: from dotenv import find_dotenv default_path = find_dotenv(usecwd=True) except (ImportError, Exception): default_path = "" if default_path and os.path.isfile(default_path): _load_and_collect(f"Default .env: {default_path}") seen_paths.add(os.path.abspath(default_path)) for filepath in _ENV_FILES: if not filepath: continue abs_path = os.path.abspath(filepath) if abs_path in seen_paths: continue seen_paths.add(abs_path) if not os.path.isfile(filepath): continue _load_and_collect(filepath, dotenv_path=filepath) return newly_loaded ``` ### Technical Analysis The loader parses all variables from: - The nearest `.env` found by searching upward from the current working directory. - `~/.env`. - `~/.bashrc`. - `~/.profile`. - The S ...[truncated 2265 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/mps_dubbing.py:223
Finding

Authenticated Tencent SDK Requests Can Be Redirected to an Arbitrary Endpoint

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/mps_gen_compare.py:124
Finding

Stored Local Cross-Site Scripting in Generated Comparison Pages

Content
View full analysis
{title} {_gen_css()}

{page_icon} {title}

Generated: {datetime.now().strftime('%Y-%m-%d %H:%M:%S')}

{''.join(sections_html)}

Slide the divider to compare

{_gen_js(pairs)} """ ``` Labels, titles, filenames, and URLs are inserted without escaping: ```python def _gen_video_section(idx, orig_url, enh_url, pair_title, ll, rl, orig_name, enh_name): sid = f"v{idx}" title_html = f'
{pair_title}
' if pair_title else '' return f"""
{title_html}
Original: {orig_name}  |  Enhanced: {enh_name}
{ll}
{rl}
""" ``` Attacker-controlled values can come from a JSON configuration file: ```python def load_pairs_from_config(config_path): with open(config_path, 'r', encoding='utf-8') as f: config = json.load(f) pairs = [] for item in config.get('pairs', []): pair = { 'original': item['original'], 'enhanced': item['enhanced'], 'type' ...[truncated 2713 chars]
Remediation
View remediation
` elements. - Event-handler attributes. - Encoded and mixed-case dangerous URL schemes. 9. Treat every value loaded from a comparison JSON file as untrusted, even if the file is local. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (190)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

描述强调的是面向用户的腾讯云 MPS 媒体处理与 AI 能力集合,但这段代码并未执行任何转码、增强、字幕、擦除、配音、图像编辑、内容理解、COS、任务查询或用量查询等操作。它的唯一实际作用是做本地 Python 运行环境准备:解析 requirements.txt、检查已安装包版本、必要时用 pip 升级依赖,并处理 warning。虽然这类代码可作为技能的辅助初始化逻辑,但就该代码块本身而言,其行为与声明的能力集合不一致,且包含未在声明中体现的本地环境修改能力(自动安装/升级依赖、调用子进程)。因此应判定为描述与代码行为存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

There is a material description-to-code mismatch. The declared purpose describes an extremely broad skill spanning many domains: transcoding, video enhancement, audio separation, subtitles/ASR, dubbing/TTS, image understanding, e-commerce image editing, AIGC image/video/audio generation, aspect conversion, document-to-video, content understanding, highlight extraction, AI commentary, QC, COS bucket/file management, task queries, usage queries, and compare-page generation. In contrast, this code chunk only implements image-oriented MPS processing through ProcessImage, with concrete support for image format conversion, enhancement, erasure, blind watermarking, beauty/filter effects, resizing, a few image schedule presets, and support utilities like upload/poll/download/compare. It does not implement the vast majority of the declared capabilities, especially audio/video processing, AIGC generation, content understanding, COS listing/bucket management, or usage/task-query commands. While over-declaration alone can sometimes be acceptable at full-skill level, the prompt asks whether the supplied code chunk actually matches the declared description; here the declared description materially overstates the chunk’s scope and primary purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

该代码块的实际用途是支持性基础设施,而不是描述中的业务能力实现。它主要访问本地环境与配置文件(.env、/.bashrc、/.profile),读取腾讯云相关密钥和桶/地域配置,并提供检查、dry-run、verbose、报错提示等诊断功能。虽然这可被视为 MPS Skill 的辅助组件,但就该代码块本身而言,其主要行为与声明的大量媒体处理与云存储操作能力明显不一致,因此应判定为 description-behavior mismatch。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

该代码块的实际用途明显比声明狭窄:它不是一个通用的“腾讯云 MPS 音视频与图片处理、AI 生成、内容理解”总入口,而是一个针对“AI 解说二创”的专用脚本。核心行为是构造 ProcessMedia 请求,固定模板 ID=35,设置 reel.processType=narrate,并可选关闭字幕擦除、设置输出数量、回调、COS 输入输出、轮询任务。这与声明中罗列的大量图像/视频/音频/AIGC/COS/质检/理解类能力不符,属于能力范围被严重夸大。另一个具体不一致点是脚本对外宣称支持多集视频 extra_urls,但代码中 build_request_params 并未把 extra_urls 写入请求参数,因此这项描述也不能被当前代码片段充分支持。综上,应判定声明与代码实际行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

该描述与此代码块不准确匹配。声明把技能描述成一个广泛的腾讯云 MPS 媒体处理与 AI 能力集合,但这段代码并不进行转码、增强、字幕、AIGC、内容理解等处理请求提交,而是围绕“任务轮询/查询”与“结果后处理”展开:调用 DescribeTaskDetail / DescribeImageTaskDetail 查询任务状态,打印摘要,提取输出,生成预签名 URL,支持本地文件上传 COS、自动下载输出到本地、生成对比页面。虽然声明中确实提到【任务】查询MPS任务、【COS】上传下载、【对比】生成对比页面,因此部分功能被覆盖,但就这段代码本身而言,其实际主用途是任务查询与文件辅助处理,而非声明中的大部分处理能力。因此应判定为描述与代码行为存在实质不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

md
| 去除字幕、擦除水印、人脸/车牌模糊、画面内容擦除/遮挡(**仅限视频**) | `mps_erase.py` | [mps_erase.md](references/mps_erase.md) | **图片**中的文字/水印擦除请用 `mps_imageprocess.py` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

md
| 去除字幕、擦除水印、人脸/车牌模糊、画面内容擦除/遮挡(**仅限视频**) | `mps_erase.py` | [mps_erase.md](references/mps_erase.md) | **图片**中的文字/水印擦除请用 `mps_imageprocess.py` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 165)May include surrounding context.

md
| 去除字幕、擦除水印、人脸/车牌模糊、画面内容擦除/遮挡(**仅限视频**) | `mps_erase.py` | [mps_erase.md](references/mps_erase.md) | **图片**中的文字/水印擦除请用 `mps_imageprocess.py` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 200)May include surrounding context.

md
| 去除字幕、擦除水印、人脸/车牌模糊、画面内容擦除/遮挡(**仅限视频**) | `mps_erase.py` | [mps_erase.md](references/mps_erase.md) | **图片**中的文字/水印擦除请用 `mps_imageprocess.py` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

md
| 去除字幕、擦除水印、人脸/车牌模糊、画面内容擦除/遮挡(**仅限视频**) | `mps_erase.py` | [mps_erase.md](references/mps_erase.md) | **图片**中的文字/水印擦除请用 `mps_imageprocess.py` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

md
| 去除字幕、擦除水印、人脸/车牌模糊、画面内容擦除/遮挡(**仅限视频**) | `mps_erase.py` | [mps_erase.md](references/mps_erase.md) | **图片**中的文字/水印擦除请用 `mps_imageprocess.py` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

md
| 去除字幕、擦除水印、人脸/车牌模糊、画面内容擦除/遮挡(**仅限视频**) | `mps_erase.py` | [mps_erase.md](references/mps_erase.md) | **图片**中的文字/水印擦除请用 `mps_imageprocess.py` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 192)May include surrounding context.

md
| 去除字幕、擦除水印、人脸/车牌模糊、画面内容擦除/遮挡(**仅限视频**) | `mps_erase.py` | [mps_erase.md](references/mps_erase.md) | **图片**中的文字/水印擦除请用 `mps_imageprocess.py` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 202)May include surrounding context.

md
| 去除字幕、擦除水印、人脸/车牌模糊、画面内容擦除/遮挡(**仅限视频**) | `mps_erase.py` | [mps_erase.md](references/mps_erase.md) | **图片**中的文字/水印擦除请用 `mps_imageprocess.py` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 133)May include surrounding context.

md
| 分镜拆图 / 宫格拆图 / 漫画分割 / 拆分镜头 | `mps_image_split.py` | [mps_image_split.md](references/mps_image_split.md) | 智能拆分分镜/宫格漫画为单帧图片,支持擦文字控制(ScheduleId=30050);耗时较长约 2 分钟

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 145)May include surrounding context.

md
| AI解说二创 / 短剧解说 / 自动生成短剧解说视频 / 短剧解说混剪 | `mps_narrate.py` | [mps_narrate.md](references/mps_narrate.md) | 必须从预设场景中选择;不支持自定义脚本;多集视频详见 references |

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script documentation explicitly states that it uses MPS VideoRemake to modify videos so they can evade platform duplicate-content detection. This is a direct abuse-enabling capability intended to circumvent trust and anti-abuse controls on third-party platforms, which materially increases the likelihood of policy evasion, spam distribution, and deceptive reposting workflows.

Content

No source excerpt is available for this finding.

Ssd 2

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file is not merely a neutral media-processing wrapper; it is explicitly framed as a tool to alter videos to avoid duplicate-detection systems. In the context of this skill, that framing makes the capability substantially more dangerous because the operational purpose is evasion rather than benign editing, enabling users to mass-produce derivative content that bypasses platform safeguards.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
92% confidence
Finding

The docstring and CLI text describe templates 201/301/302 as watermark/face/plate modes, with custom erase parameters only for subtitle templates. However, build_smart_erase_task unconditionally sets OverrideParameter.EraseType to "subtitle" whenever custom parameters are present, which would semantically target subtitle-erasure override logic rather than the selected non-subtitle template behavior if validation is bypassed or reused programmatically.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

Automatically loading credentials from a .env discovered by searching upward from the current working directory creates a trust-boundary problem: a user can run the skill from an untrusted project tree and silently import attacker-controlled configuration. In a skill that performs cloud operations, this can redirect jobs to attacker-controlled accounts, buckets, or regions, or cause the tool to operate with unintended credentials.

Content

Scanner excerpt · scripts/mps_load_env.py (reported line 8)May include surrounding context.

python
实现说明:
  使用 python-dotenv 库的 load_dotenv 函数加载 dotenv 风格的配置文件。
  按以下顺序加载(已存在的环境变量不会被覆盖,先加载者优先):
    1. 默认行为:通过 find_dotenv(usecwd=True) 从当前目录向上递归找最近的 .env 并加载
    2. ~/.env                (用户级 dotenv)
    3. ~/.bashrc             (shell 启动文件,兼容 export VAR=... 写法)
    4. ~/.profile            (登录 shell 启动文件)

Credential Access

High
Category
Privilege Escalation
Confidence
82% confidence
Finding

The documented behavior includes loading ~/.env, which is a broad credential source unrelated to this skill. Pulling secrets from generic user-level dotenv files increases the chance of unintended secret use and mixes trust domains, especially in an agent skill context where execution location may vary.

Content

Scanner excerpt · scripts/mps_load_env.py (reported line 9)May include surrounding context.

python
使用 python-dotenv 库的 load_dotenv 函数加载 dotenv 风格的配置文件。
  按以下顺序加载(已存在的环境变量不会被覆盖,先加载者优先):
    1. 默认行为:通过 find_dotenv(usecwd=True) 从当前目录向上递归找最近的 .env 并加载
    2. ~/.env                (用户级 dotenv)
    3. ~/.bashrc             (shell 启动文件,兼容 export VAR=... 写法)
    4. ~/.profile            (登录 shell 启动文件)
    5. <SKILL_DIR>/.env      (脚本所在 skill 目录的 dotenv)

Credential Access

High
Category
Privilege Escalation
Confidence
83% confidence
Finding

Loading <SKILL_DIR>/.env for cloud credentials is not inherently unsafe, but in combination with other auto-discovery behavior it encourages secrets to be stored in plaintext files inside or near code. In agent environments, skill packages can be shared, copied, or inspected, raising exposure risk for long-lived API credentials.

Content

Scanner excerpt · scripts/mps_load_env.py (reported line 12)May include surrounding context.

python
2. ~/.env                (用户级 dotenv)
    3. ~/.bashrc             (shell 启动文件,兼容 export VAR=... 写法)
    4. ~/.profile            (登录 shell 启动文件)
    5. <SKILL_DIR>/.env      (脚本所在 skill 目录的 dotenv)

  目标变量(全部为必需):
    TENCENTCLOUD_SECRET_ID       (必需)

Credential Access

High
Category
Privilege Escalation
Confidence
87% confidence
Finding

The candidate file list includes generic credential-bearing files such as ~/.env, ~/.bashrc, and ~/.profile. Treating shell startup files as dotenv input broadens the attack surface and can ingest unrelated exports, making credential sourcing non-deterministic and easier to manipulate.

Content

Scanner excerpt · scripts/mps_load_env.py (reported line 72)May include surrounding context.

python
# 候选 dotenv 文件列表(按加载顺序,先加载者优先;load_dotenv 默认 override=False)
# 此外,load_env_files() 会先调用一次无参 load_dotenv(),
# 借助 find_dotenv(usecwd=True) 从当前工作目录向上递归查找最近的 .env 文件并加载。
_ENV_FILES = [
    os.path.expanduser("~/.env"),
    os.path.expanduser("~/.bashrc"),

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The implementation combines upward .env discovery with a list of broad user-level files, creating multiple uncontrolled sources for credentials. For a media-processing skill that can upload/download from COS and invoke MPS tasks, unintended credential loading materially increases the chance of cross-account access or misuse.

Content

Scanner excerpt · scripts/mps_load_env.py (reported line 74)May include surrounding context.

python
# 此外,load_env_files() 会先调用一次无参 load_dotenv(),
# 借助 find_dotenv(usecwd=True) 从当前工作目录向上递归查找最近的 .env 文件并加载。
_ENV_FILES = [
    os.path.expanduser("~/.env"),
    os.path.expanduser("~/.bashrc"),
    os.path.expanduser("~/.profile"),
    os.path.dirname(os.path.dirname(os.path.abspath(__file__)))

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/mps_load_env.py (reported line 101)May include surrounding context.

python
def _load_and_collect(path_label, dotenv_path=None):
        """加载一个 dotenv 文件并收集新增变量。"""
        before = dict(os.environ)
        try:
            ok = load_dotenv(dotenv_path=dotenv_path, override=False) if dotenv_path else load_dotenv(override=False)
        except (OSError, IOError) as e:

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:40