Back to skill

Security audit

Material Generator

Security checks for vulnerabilities and agentic risk

Overview

The skill is a simple UE material-generator note, but it publishes a plaintext MiniMax API key that users should treat as compromised.

Do not install or reuse this skill as-is with the included key. The publisher should revoke and rotate the MiniMax key, replace it with an environment-variable or secret-manager instruction, and ensure any deployed app keeps provider credentials server-side with rate limits and user controls.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:22
Finding

Hardcoded MiniMax API Credential in Skill Documentation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill documentation exposes a live-looking API secret directly in a client-side skill package. Anyone who can read the file can reuse the key to invoke the third-party model API, leading to unauthorized usage, billing abuse, account compromise, and possible access to associated service capabilities or logs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill documentation is presented only in Chinese, and there is no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking context. This creates a natural-language policy concern because it effectively imposes a locale without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
- `public/` — 静态JSON示例文件

## API配置
- Base: `https://api.minimaxi.com/v1`
- Model: `MiniMax-M2.7`
- Key: `sk-cp-g2MZf43bhLucC0sCMI-BeaXycKl5MDj_dPN_mPKn7IfqlAL1bS8YP-ERiEi9ZJMLu7I2XXIMjw9Xb8x-9iONlnOg24dBV5imId_W5v1oyivKwZCMr7nix6c`

Static analysis

No suspicious patterns detected.