Back to skill

Security audit

kameo

Security checks for vulnerabilities and agentic risk

Overview

The skill's video-generation purpose is coherent, but it ships unsafe credential handling and a shell helper vulnerability that can expose secrets or execute injected code.

Review this carefully before installing. Use your own Kameo key, treat the documented kam_ value as exposed, avoid the registration helper as written, and do not pass real passwords on the command line. Do not run the enhanced prompt helper on untrusted filenames or dialogue until the heredoc interpolation is fixed. Only upload portraits when you have consent and are comfortable sending the image and prompt to Kameo and, for enhanced prompts, Google Gemini.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/enhance_prompt.sh:57
Finding

Arbitrary Python Code Execution Through Unquoted Heredoc Input Interpolation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:27
Finding

API Credential-Like Secret Embedded Repeatedly in Documentation

Content
View full analysis
~/.config/kameo/credentials.json << EOF { "api_key": "kam_I3rdx43IymFNbfBw1c0ZbSc7o3aUfQgz8cljZA6T7fs" } EOF ``` ```bash curl -X POST https://api.kameo.chat/api/public/generate \ -H "X-API-Key: kam_I3rdx43IymFNbfBw1c0ZbSc7o3aUfQgz8cljZA6T7fs" \ -H "Content-Type: application/json" \ -d @request.json ``` ### Technical Analysis The documentation contains a realistic Kameo API key rather than an unmistakable placeholder. Because the same value appears in environment-variable, credential-file, and authenticated HTTP examples, users may reasonably interpret it as a usable credential. Static inspection cannot establish whether the key remains active. Nevertheless, any credential committed to distributed documentation must be treated as disclosed. Removing it only from the current files is insufficient if it has also entered repository history, package archives, caches, or downloaded Skill copies. ### Attack Path 1. An attacker downloads the Skill or inspects its repository or package history. 2. The attacker extracts the `kam_...` value from `SKILL.md` or `USAGE.md`. 3. If the key is active, the attacker sends it in the `X-API-Key` header to Kameo API endpoints. 4. Requests are attributed to the account associated ...[truncated 592 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/register.sh:7
Finding

Account Password Accepted as a Command-Line Argument

Content
View full analysis
" echo "" echo "This will:" ``` ```bash LOGIN_RESULT=$(curl -s -X POST "$SUPABASE_URL/auth/v1/token?grant_type=password" \ -H "apikey: $SUPABASE_ANON_KEY" \ -H "Content-Type: application/json" \ -d "{\"email\":\"$EMAIL\",\"password\":\"$PASSWORD\"}") ``` The documented invocation exposes the password directly: ```bash scripts/register.sh your@email.com YourPassword123 ``` The helper is also configured with placeholders rather than an operational authentication endpoint: ```bash SUPABASE_URL="https://YOUR_PROJECT.supabase.co" SUPABASE_ANON_KEY="YOUR_SUPABASE_ANON_KEY" ``` ### Technical Analysis The script requires the account password as positional argument `$2`. Commands entered interactively are commonly retained in shell-history files. While the script runs, command-line arguments may also be visible through local process-inspection facilities to users or monitoring software with sufficient access. Although the password is subsequently held in a shell variable, that does not remove it from the original command invocation or any history already written. The documentation explicitly encourages this insecure invocation pattern. The placeholder Supabase URL and anonymous key mean the registration helper is not operational as shipped. This does not itself disclose a secret, but it may cause users to edit the script and embed additional service configuration directly in source code. ### Attack Path 1. A user follows `USAGE.md` and invokes `register.sh` with an actual email address and password on the command line. 2. The command is r ...[truncated 939 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (50)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documentation goes beyond content generation into registration, login, API-key creation, and local credential storage. Those account lifecycle operations are materially different from the declared purpose and increase the chance of collecting secrets or performing sensitive actions users did not intend.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documentation goes beyond content generation into registration, login, API-key creation, and local credential storage. Those account lifecycle operations are materially different from the declared purpose and increase the chance of collecting secrets or performing sensitive actions users did not intend.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documentation goes beyond content generation into registration, login, API-key creation, and local credential storage. Those account lifecycle operations are materially different from the declared purpose and increase the chance of collecting secrets or performing sensitive actions users did not intend.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

The documentation contains what appears to be a live Kameo API key in plaintext and instructs users to store it in a local credentials file. Exposed API keys can be abused by anyone who sees the repository or logs, leading to unauthorized account use, credit consumption, and possible access to associated service data.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

export KAMEO_API_KEY="kam_I3rdx43IymFNbfBw1c0ZbSc7o3aUfQgz8cljZA6T7fs"

text

Or store in `~/.config/kameo/credentials.json`:
```json
{
  "api_key": "kam_I3rdx43IymFNbfBw1c0ZbSc7o3aUfQgz8cljZA6T7fs"

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The usage guide embeds what appears to be a real API key and instructs users to export or store it in plaintext without any warning about secret handling. Exposed credentials can be reused by anyone with access to the repository or logs, enabling unauthorized API usage, billing abuse, and possible account compromise.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The documentation instructs users to place an API key in a plaintext credentials file under the home directory. Plaintext long-lived secrets are easily exposed through backups, local compromise, shell history, support bundles, or accidental repository inclusion.

Content

Scanner excerpt · USAGE.md (reported line 13)May include surrounding context.

md
# 或保存到配置文件
mkdir -p ~/.config/kameo
cat > ~/.config/kameo/credentials.json << EOF
{
  "api_key": "kam_I3rdx43IymFNbfBw1c0ZbSc7o3aUfQgz8cljZA6T7fs"
}

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · USAGE.md (reported line 163)May include surrounding context.

md
# Check Kameo credit balance

API_KEY="${KAMEO_API_KEY:-}"
if [ -z "$API_KEY" ] && [ -f ~/.config/kameo/credentials.json ]; then
    API_KEY=$(jq -r '.api_key' ~/.config/kameo/credentials.json)
fi

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/check_credits.sh (reported line 5)May include surrounding context.

sh
# Check Kameo credit balance

API_KEY="${KAMEO_API_KEY:-}"
if [ -z "$API_KEY" ] && [ -f ~/.config/kameo/credentials.json ]; then
    API_KEY=$(jq -r '.api_key' ~/.config/kameo/credentials.json)
fi

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/check_credits.sh (reported line 6)May include surrounding context.

sh
# Check Kameo credit balance

API_KEY="${KAMEO_API_KEY:-}"
if [ -z "$API_KEY" ] && [ -f ~/.config/kameo/credentials.json ]; then
    API_KEY=$(jq -r '.api_key' ~/.config/kameo/credentials.json)
fi

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/generate_video.sh (reported line 13)May include surrounding context.

sh
# Check Kameo credit balance

API_KEY="${KAMEO_API_KEY:-}"
if [ -z "$API_KEY" ] && [ -f ~/.config/kameo/credentials.json ]; then
    API_KEY=$(jq -r '.api_key' ~/.config/kameo/credentials.json)
fi

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/generate_video.sh (reported line 14)May include surrounding context.

sh
# Check Kameo credit balance

API_KEY="${KAMEO_API_KEY:-}"
if [ -z "$API_KEY" ] && [ -f ~/.config/kameo/credentials.json ]; then
    API_KEY=$(jq -r '.api_key' ~/.config/kameo/credentials.json)
fi

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/generate_video.sh (reported line 21)May include surrounding context.

sh
# Check Kameo credit balance

API_KEY="${KAMEO_API_KEY:-}"
if [ -z "$API_KEY" ] && [ -f ~/.config/kameo/credentials.json ]; then
    API_KEY=$(jq -r '.api_key' ~/.config/kameo/credentials.json)
fi

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The script writes a reusable API key in plaintext to a predictable file path under the user's home directory. Even with mode 600, plaintext credential storage can be harvested by malware running as the user, exposed through insecure backups, or inadvertently disclosed during support/debugging.

Content

Scanner excerpt · scripts/register.sh (reported line 81)May include surrounding context.

sh
# Save to config
    mkdir -p ~/.config/kameo
    cat > ~/.config/kameo/credentials.json << EOF
{
  "api_key": "$KAMEO_KEY",
  "email": "$EMAIL"

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

The credentials file is explicitly persisted and retained for later use, creating an ongoing target for local compromise. The file path is disclosed to the user, which is transparent, but the underlying risk remains because a long-lived API secret is stored on disk.

Content

Scanner excerpt · scripts/register.sh (reported line 87)May include surrounding context.

sh
"email": "$EMAIL"
}
EOF
    chmod 600 ~/.config/kameo/credentials.json
    
    echo "✅ Saved to ~/.config/kameo/credentials.json"
    echo ""

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

The script instructs the user to export the API key into the current shell session, which can increase exposure through shell history, environment inspection by same-user processes, or accidental leakage into child processes. While common in CLI tooling, it still handles a live credential in a comparatively weak way.

Content

Scanner excerpt · scripts/register.sh (reported line 89)May include surrounding context.

sh
EOF
    chmod 600 ~/.config/kameo/credentials.json
    
    echo "✅ Saved to ~/.config/kameo/credentials.json"
    echo ""
    echo "Export for current session:"
    echo "  export KAMEO_API_KEY='$KAMEO_KEY'"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill documentation describes capabilities that require shell, network, and environment-variable access, but it does not declare an explicit tool/permission scope. That omission weakens reviewability and can cause the skill to be executed with broader access than users expect, especially since it also references local credential files and outbound API calls.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: kameo
description: Generate expressive talking-head videos from static images using Kameo AI. Converts static avatars/portraits into dynamic 5-second videos with realistic facial expressions, lip-sync, and motion. Use when you need to bring static images to life, create AI character videos, demonstrate visual communication, or generate talking avatars from photos.
---

# Kameo AI - Talking Head Video Generation

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation explains how to upload images and prompts to Kameo but does not clearly warn users that their media and text are transmitted to an external API and resulting videos are hosted on a CDN. Users may unknowingly send sensitive faces, prompts, or personal content to third-party infrastructure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Including a registration helper in a generation skill expands the operational scope into account creation and key provisioning. That can normalize handling user credentials and sensitive setup steps in a context where users expect only media generation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

Generate Video

bash
curl -X POST https://api.kameo.chat/api/public/generate \
  -H "X-API-Key: kam_I3rdx43IymFNbfBw1c0ZbSc7o3aUfQgz8cljZA6T7fs" \
  -H "Content-Type: application/json" \
  -d '{

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The skill encourages persistent storage of an API key in ~/.config/kameo/credentials.json, increasing the lifetime and exposure window of the secret beyond a single session. Persistent secrets raise the risk of unauthorized reuse after host compromise, backup leakage, or accidental disclosure.

Content

Scanner excerpt · USAGE.md (reported line 12)May include surrounding context.

md
export KAMEO_API_KEY="kam_I3rdx43IymFNbfBw1c0ZbSc7o3aUfQgz8cljZA6T7fs"

# 或保存到配置文件
mkdir -p ~/.config/kameo
cat > ~/.config/kameo/credentials.json << EOF
{
  "api_key": "kam_I3rdx43IymFNbfBw1c0ZbSc7o3aUfQgz8cljZA6T7fs"

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes a skill for generating talking-head videos from static images using Kameo AI. The usage documentation also instructs users to register an account and automatically create API keys, which is an account-management/onboarding capability not stated as part of the skill's purpose.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · USAGE.md (reported line 278)May include surrounding context.

bash
# 配置信息(无需认证)
curl https://api.kameo.chat/api/public/config

# 价格信息(无需认证)
curl https://api.kameo.chat/api/public/pricing

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

This example includes a concrete API key directly in the authenticated curl command, turning otherwise expected external transmission into credential disclosure. Anyone reading the file can reuse the token to make authenticated API calls, incur charges, or access associated account resources.

Content

Scanner excerpt · USAGE.md (reported line 287)May include surrounding context.

md
curl -H "X-API-Key: kam_..." https://api.kameo.chat/api/public/credits

# 生成视频
curl -X POST https://api.kameo.chat/api/public/generate \
  -H "X-API-Key: kam_I3rdx43IymFNbfBw1c0ZbSc7o3aUfQgz8cljZA6T7fs" \
  -H "Content-Type: application/json" \
  -d @request.json

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The package description promotes generating talking-head videos from static images but provides no warning about consent, impersonation, or privacy risks. In a skill that operates on user-provided portraits and can create realistic facial motion and lip-sync, omission of these safeguards can enable deceptive or non-consensual use and mislead downstream users or agents about the sensitivity of the capability.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal, suspicious.potential_exfiltration

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:32

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
USAGE.md:9

Shell script base64-encodes a local file and sends it over the network.

Critical
Code
suspicious.potential_exfiltration
Location
scripts/generate_video.sh:57