Back to skill

Security audit

Max Studio Api

Security checks for vulnerabilities and agentic risk

Overview

This Max Studio API skill is mostly coherent, but it asks users to pass a Google access token and API key through command-line arguments and sends the Google token to a third-party service.

Review carefully before installing. Use this only if you are comfortable sending a Google access token to Max Studio, and avoid pasting real secrets directly into shell commands. Prefer an isolated environment, rotate/revoke tokens after use, restrict downloads to trusted media URLs and safe output directories, and pin dependencies before operational use.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/max_studio.py:129
Finding

Google Access Token Disclosed to a Third-Party Service

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:56
Finding

Sensitive Credentials Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/max_studio.py:89
Finding

Unrestricted URL Download and Arbitrary User-Writable File Overwrite

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Third-Party Dependency Reduces Supply-Chain Integrity

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The documented behavior does not fully match the implemented behavior: an API key status-check capability exists but is not declared, while claimed batch packaging functionality is not present. Such mismatches undermine trust and can hide sensitive or unexpected actions from users and reviewers.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

The skill instructs users to paste a Google/Max Studio JWT and API key directly into command-line arguments. Secrets passed on the CLI are often exposed through shell history, process listings, logs, or job runners, creating a realistic path for credential leakage and downstream account abuse.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
To create images or videos, follow these steps:

1. Register and obtain your API key from [https://max-studio.shop](https://max-studio.shop).
2. Obtain your JWT (Google access token) manually from your authenticated Google/Max Studio flow, then paste it here.
3. Provide the API key and JWT directly using the `--api-key` and `--jwt` parameters when running the skill.

Refer to the documentation in the skill folder for full usage details.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api_docs.md (reported line 156)May include surrounding context.

md
| `ratio` | string | ❌ | `LANDSCAPE` | Tỉ lệ khung hình |
| `quantity` | int | ❌ | `1` | Số video muốn tạo (1–4) |
| `model` | string | ❌ | `Veo_3.1-Fast` | Model Veo |
| `jwt` | string | ✅ | — | Google Access Token |

**`ratio` hợp lệ:**

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api_docs.md (reported line 203)May include surrounding context.

md
| `ratio` | string | ❌ | `LANDSCAPE` | Tỉ lệ khung hình |
| `quantity` | int | ❌ | `1` | Số video muốn tạo (1–4) |
| `model` | string | ❌ | `Veo_3.1-Fast` | Model Veo |
| `jwt` | string | ✅ | — | Google Access Token |

**`ratio` hợp lệ:**

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api_docs.md (reported line 256)May include surrounding context.

md
| `ratio` | string | ❌ | `LANDSCAPE` | Tỉ lệ khung hình |
| `quantity` | int | ❌ | `1` | Số video muốn tạo (1–4) |
| `model` | string | ❌ | `Veo_3.1-Fast` | Model Veo |
| `jwt` | string | ✅ | — | Google Access Token |

**`ratio` hợp lệ:**

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api_docs.md (reported line 308)May include surrounding context.

md
| `ratio` | string | ❌ | `LANDSCAPE` | Tỉ lệ khung hình |
| `quantity` | int | ❌ | `1` | Số video muốn tạo (1–4) |
| `model` | string | ❌ | `Veo_3.1-Fast` | Model Veo |
| `jwt` | string | ✅ | — | Google Access Token |

**`ratio` hợp lệ:**

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api_docs.md (reported line 363)May include surrounding context.

md
| `ratio` | string | ❌ | `LANDSCAPE` | Tỉ lệ khung hình |
| `quantity` | int | ❌ | `1` | Số video muốn tạo (1–4) |
| `model` | string | ❌ | `Veo_3.1-Fast` | Model Veo |
| `jwt` | string | ✅ | — | Google Access Token |

**`ratio` hợp lệ:**

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api_docs.md (reported line 424)May include surrounding context.

md
| `ratio` | string | ❌ | `LANDSCAPE` | Tỉ lệ khung hình |
| `quantity` | int | ❌ | `1` | Số video muốn tạo (1–4) |
| `model` | string | ❌ | `Veo_3.1-Fast` | Model Veo |
| `jwt` | string | ✅ | — | Google Access Token |

**`ratio` hợp lệ:**

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api_docs.md (reported line 474)May include surrounding context.

md
| `ratio` | string | ❌ | `LANDSCAPE` | Tỉ lệ khung hình |
| `quantity` | int | ❌ | `1` | Số video muốn tạo (1–4) |
| `model` | string | ❌ | `Veo_3.1-Fast` | Model Veo |
| `jwt` | string | ✅ | — | Google Access Token |

**`ratio` hợp lệ:**

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api_docs.md (reported line 520)May include surrounding context.

md
| `ratio` | string | ❌ | `LANDSCAPE` | Tỉ lệ khung hình |
| `quantity` | int | ❌ | `1` | Số video muốn tạo (1–4) |
| `model` | string | ❌ | `Veo_3.1-Fast` | Model Veo |
| `jwt` | string | ✅ | — | Google Access Token |

**`ratio` hợp lệ:**

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api_docs.md (reported line 562)May include surrounding context.

md
| `ratio` | string | ❌ | `LANDSCAPE` | Tỉ lệ khung hình |
| `quantity` | int | ❌ | `1` | Số video muốn tạo (1–4) |
| `model` | string | ❌ | `Veo_3.1-Fast` | Model Veo |
| `jwt` | string | ✅ | — | Google Access Token |

**`ratio` hợp lệ:**

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api_docs.md (reported line 594)May include surrounding context.

md
| Field | Type | Bắt buộc | Mặc định | Mô tả |
|-------|------|----------|----------|-------|
| `image_path` | string | ✅ | — | URL của ảnh cần upload |
| `jwt` | string | ✅ | — | Google Access Token |
| `ratio` | string | ❌ | `auto` | Tỉ lệ (mặc định `auto`) |

> ℹ️ Endpoint này **đồng bộ** — response trả ngay kết quả, không cần poll check-status.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api_docs.md (reported line 724)May include surrounding context.

md
| Message | Nguyên nhân | Xử lý |
|---------|------------|-------|
| `JWT required` | Không truyền `jwt` | Thêm `jwt` vào body |
| `JWT has expired!` | JWT Google hết hạn hoặc không hợp lệ | Refresh access token |
| `Credit = 0, provide new JWT with enough credit to create media` | Google account hết credit | Dùng account Google còn credit |
| `JWT invalid or the balance is too low, please provide new JWT and try again` | Credit ≤ 10 | Dùng account Google còn đủ credit |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/max_studio.py (reported line 42)May include surrounding context.

python
def get_jwt(value=None, required=True):
    jwt = value
    if required and not jwt:
        raise MaxStudioError("Missing JWT (Google access token). Provide it via --jwt for this endpoint.")
    return jwt

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/max_studio.py (reported line 107)May include surrounding context.

python
def get_jwt(value=None, required=True):
    jwt = value
    if required and not jwt:
        raise MaxStudioError("Missing JWT (Google access token). Provide it via --jwt for this endpoint.")
    return jwt

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill enables network-capable behavior but does not declare any tool scope or permissions boundaries. That makes the capability less transparent to reviewers and enforcement systems, increasing the chance that network access is granted or used without explicit approval.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
75% confidence
Finding

The document is written entirely in Vietnamese for external integrators and does not offer an alternative language or note that the locale is intentionally restricted. Under SQP-3, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The upload endpoint instructs integrators to submit arbitrary third-party image URLs without any warning about privacy, ownership, server-side fetching risks, or retention/processing behavior. In practice this can lead users to send private or signed URLs to a third party, exposing sensitive media or pre-authenticated storage links to the service operator.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file documents this skill as covering image/video generation, upload, polling, downloads, and packaging, but the validation table includes references to Grok-specific ratio/resolution rules and a captcha endpoint requiring type. Those documented behaviors are not described anywhere in the endpoint sections, so the inline documentation contradicts the apparent scope of the API described in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The download command accepts an arbitrary URL and arbitrary local output path, then writes the fetched content directly to disk without validating the scheme, hostname, destination path, or file type. If untrusted input reaches this CLI, it can be abused for SSRF-style internal fetching or overwriting user-accessible files, which is more dangerous in an agent or automation context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code inserts a Google access token into the request payload and sends it to an external service, but there is no confirmation prompt or user-facing disclosure at the point of transmission. Although the argument help names the token, the code does not clearly warn that a sensitive credential will be sent off-host to the API.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The section says users asking where to obtain an API key should be told to get it themselves from https://max-studio.shop, but later the same document says integrators should contact the technical team to be issued an API key. These instructions conflict about the intended source of credentials, which can mislead users and integrators about the authentication flow.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency manifest specifies requests without a version constraint, which makes builds non-reproducible and can cause the environment to resolve to a vulnerable or incompatible release. In a skill that performs API calls, uploads, polling, and media downloads, this increases supply-chain and maintenance risk because security posture depends on whatever version gets installed at deployment time.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
93% confidence
Finding

requests has multiple known advisories, and because the manifest does not pin a version, it is impossible to verify whether installation will select an affected release. This is more concerning in this skill's context because it relies on outbound HTTP interactions and media downloads, where library flaws could contribute to credential leakage, TLS/verification issues, or unsafe request handling.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.