Back to skill

Security audit

china-video-gen

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned for AI video generation, but it asks users to install mutable third-party skills and persist an API key without enough scoping or secret-handling guidance.

Review this skill before installing. It is not showing malicious behavior, but use a dedicated low-quota SiliconFlow key, avoid storing it permanently unless the file is locked down, and verify or pin the china-image-gen and china-tts dependencies before granting them access to your workspace or credentials.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
references/dependencies.md:76
Finding

Persistent Plaintext Storage of SiliconFlow API Credential

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/dependencies.md:34
Finding

Unpinned Installation of Third-Party OpenClaw Skills

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/dependencies.md (reported line 15)May include surrounding context.

md
brew install ffmpeg

# Ubuntu/Debian
sudo apt update && sudo apt install -y ffmpeg

# CentOS/RHEL
sudo yum install -y ffmpeg

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description advertises video generation capabilities but does not clearly warn that user text and derived prompts will be transmitted to external services for image and speech generation. This creates a privacy and consent risk, especially if users provide sensitive marketing drafts, personal data, or proprietary material expecting only local handling.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are very broad and map to common user requests like 'make a promo video' or 'turn this text into a video', which increases the chance the skill auto-activates in situations where the user did not explicitly consent to using external generation services. In this skill’s context, that means user-provided content may be sent to third-party image/TTS APIs and local media-processing tools without a clear, narrow activation boundary.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

text
检查 ffmpeg 是否已安装:
- macOS:   brew install ffmpeg
- Ubuntu:  sudo apt install ffmpeg
- Windows: 从 https://ffmpeg.org/download.html 下载

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Step 2 specifies that the image prompt should be in English and the narration should be in Chinese, even though Step 1 says the user language may be Chinese, English, or mixed. This creates a fixed language requirement that overrides the user's stated preference without clear justification or opt-in.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/dependencies.md (reported line 15)May include surrounding context.

md
brew install ffmpeg

# Ubuntu/Debian
sudo apt update && sudo apt install -y ffmpeg

# CentOS/RHEL
sudo yum install -y ffmpeg

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/dependencies.md (reported line 18)May include surrounding context.

md
brew install ffmpeg

# Ubuntu/Debian
sudo apt update && sudo apt install -y ffmpeg

# CentOS/RHEL
sudo yum install -y ffmpeg

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/dependencies.md (reported line 21)May include surrounding context.

md
brew install ffmpeg

# Ubuntu/Debian
sudo apt update && sudo apt install -y ffmpeg

# CentOS/RHEL
sudo yum install -y ffmpeg

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The document instructs users to export a live API key and optionally persist it in ~/.openclaw/.env, but it does not warn that this credential is sensitive, should not be committed to source control, and should be protected with appropriate file permissions. This can lead to accidental credential disclosure through shell history, shared environments, backups, or checked-in dotfiles.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

All user-facing instructions in the file are presented only in Chinese, and there is no indication that the skill is region-specific or that users can opt into this locale. The policy requires flagging natural-language locale constraints when they force a specific language without user choice or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains user-facing instructional text only in Chinese, which can constitute a language/locale policy issue when no user opt-in or alternative language option is provided. The file does not state that it is intended only for a Chinese-language audience or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

Line L010 states that image prompts must be in English, which imposes a language requirement in natural-language guidance. The file does not offer opt-in, alternatives, or a documented justification for this locale/language constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.