T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/max_studio.py:129- Finding
Google Access Token Disclosed to a Third-Party Service
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Max Studio API skill is mostly coherent, but it asks users to pass a Google access token and API key through command-line arguments and sends the Google token to a third-party service.
Review carefully before installing. Use this only if you are comfortable sending a Google access token to Max Studio, and avoid pasting real secrets directly into shell commands. Prefer an isolated environment, rotate/revoke tokens after use, restrict downloads to trusted media URLs and safe output directories, and pin dependencies before operational use.
scripts/max_studio.py:129Google Access Token Disclosed to a Third-Party Service
SKILL.md:56Sensitive Credentials Exposed Through Command-Line Arguments
scripts/max_studio.py:89Unrestricted URL Download and Arbitrary User-Writable File Overwrite
requirements.txt:1Unpinned Third-Party Dependency Reduces Supply-Chain Integrity
The documented behavior does not fully match the implemented behavior: an API key status-check capability exists but is not declared, while claimed batch packaging functionality is not present. Such mismatches undermine trust and can hide sensitive or unexpected actions from users and reviewers.
The skill instructs users to paste a Google/Max Studio JWT and API key directly into command-line arguments. Secrets passed on the CLI are often exposed through shell history, process listings, logs, or job runners, creating a realistic path for credential leakage and downstream account abuse.
To create images or videos, follow these steps:
1. Register and obtain your API key from [https://max-studio.shop](https://max-studio.shop).
2. Obtain your JWT (Google access token) manually from your authenticated Google/Max Studio flow, then paste it here.
3. Provide the API key and JWT directly using the `--api-key` and `--jwt` parameters when running the skill.
Refer to the documentation in the skill folder for full usage details.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| `ratio` | string | ❌ | `LANDSCAPE` | Tỉ lệ khung hình |
| `quantity` | int | ❌ | `1` | Số video muốn tạo (1–4) |
| `model` | string | ❌ | `Veo_3.1-Fast` | Model Veo |
| `jwt` | string | ✅ | — | Google Access Token |
**`ratio` hợp lệ:**
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| `ratio` | string | ❌ | `LANDSCAPE` | Tỉ lệ khung hình |
| `quantity` | int | ❌ | `1` | Số video muốn tạo (1–4) |
| `model` | string | ❌ | `Veo_3.1-Fast` | Model Veo |
| `jwt` | string | ✅ | — | Google Access Token |
**`ratio` hợp lệ:**
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| `ratio` | string | ❌ | `LANDSCAPE` | Tỉ lệ khung hình |
| `quantity` | int | ❌ | `1` | Số video muốn tạo (1–4) |
| `model` | string | ❌ | `Veo_3.1-Fast` | Model Veo |
| `jwt` | string | ✅ | — | Google Access Token |
**`ratio` hợp lệ:**
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| `ratio` | string | ❌ | `LANDSCAPE` | Tỉ lệ khung hình |
| `quantity` | int | ❌ | `1` | Số video muốn tạo (1–4) |
| `model` | string | ❌ | `Veo_3.1-Fast` | Model Veo |
| `jwt` | string | ✅ | — | Google Access Token |
**`ratio` hợp lệ:**
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| `ratio` | string | ❌ | `LANDSCAPE` | Tỉ lệ khung hình |
| `quantity` | int | ❌ | `1` | Số video muốn tạo (1–4) |
| `model` | string | ❌ | `Veo_3.1-Fast` | Model Veo |
| `jwt` | string | ✅ | — | Google Access Token |
**`ratio` hợp lệ:**
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| `ratio` | string | ❌ | `LANDSCAPE` | Tỉ lệ khung hình |
| `quantity` | int | ❌ | `1` | Số video muốn tạo (1–4) |
| `model` | string | ❌ | `Veo_3.1-Fast` | Model Veo |
| `jwt` | string | ✅ | — | Google Access Token |
**`ratio` hợp lệ:**
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| `ratio` | string | ❌ | `LANDSCAPE` | Tỉ lệ khung hình |
| `quantity` | int | ❌ | `1` | Số video muốn tạo (1–4) |
| `model` | string | ❌ | `Veo_3.1-Fast` | Model Veo |
| `jwt` | string | ✅ | — | Google Access Token |
**`ratio` hợp lệ:**
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| `ratio` | string | ❌ | `LANDSCAPE` | Tỉ lệ khung hình |
| `quantity` | int | ❌ | `1` | Số video muốn tạo (1–4) |
| `model` | string | ❌ | `Veo_3.1-Fast` | Model Veo |
| `jwt` | string | ✅ | — | Google Access Token |
**`ratio` hợp lệ:**
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| `ratio` | string | ❌ | `LANDSCAPE` | Tỉ lệ khung hình |
| `quantity` | int | ❌ | `1` | Số video muốn tạo (1–4) |
| `model` | string | ❌ | `Veo_3.1-Fast` | Model Veo |
| `jwt` | string | ✅ | — | Google Access Token |
**`ratio` hợp lệ:**
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| Field | Type | Bắt buộc | Mặc định | Mô tả |
|-------|------|----------|----------|-------|
| `image_path` | string | ✅ | — | URL của ảnh cần upload |
| `jwt` | string | ✅ | — | Google Access Token |
| `ratio` | string | ❌ | `auto` | Tỉ lệ (mặc định `auto`) |
> ℹ️ Endpoint này **đồng bộ** — response trả ngay kết quả, không cần poll check-status.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| Message | Nguyên nhân | Xử lý |
|---------|------------|-------|
| `JWT required` | Không truyền `jwt` | Thêm `jwt` vào body |
| `JWT has expired!` | JWT Google hết hạn hoặc không hợp lệ | Refresh access token |
| `Credit = 0, provide new JWT with enough credit to create media` | Google account hết credit | Dùng account Google còn credit |
| `JWT invalid or the balance is too low, please provide new JWT and try again` | Credit ≤ 10 | Dùng account Google còn đủ credit |
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
def get_jwt(value=None, required=True):
jwt = value
if required and not jwt:
raise MaxStudioError("Missing JWT (Google access token). Provide it via --jwt for this endpoint.")
return jwt
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
def get_jwt(value=None, required=True):
jwt = value
if required and not jwt:
raise MaxStudioError("Missing JWT (Google access token). Provide it via --jwt for this endpoint.")
return jwt
The skill enables network-capable behavior but does not declare any tool scope or permissions boundaries. That makes the capability less transparent to reviewers and enforcement systems, increasing the chance that network access is granted or used without explicit approval.
The document is written entirely in Vietnamese for external integrators and does not offer an alternative language or note that the locale is intentionally restricted. Under SQP-3, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified.
The upload endpoint instructs integrators to submit arbitrary third-party image URLs without any warning about privacy, ownership, server-side fetching risks, or retention/processing behavior. In practice this can lead users to send private or signed URLs to a third party, exposing sensitive media or pre-authenticated storage links to the service operator.
The file documents this skill as covering image/video generation, upload, polling, downloads, and packaging, but the validation table includes references to Grok-specific ratio/resolution rules and a captcha endpoint requiring type. Those documented behaviors are not described anywhere in the endpoint sections, so the inline documentation contradicts the apparent scope of the API described in this file.
The download command accepts an arbitrary URL and arbitrary local output path, then writes the fetched content directly to disk without validating the scheme, hostname, destination path, or file type. If untrusted input reaches this CLI, it can be abused for SSRF-style internal fetching or overwriting user-accessible files, which is more dangerous in an agent or automation context.
This code inserts a Google access token into the request payload and sends it to an external service, but there is no confirmation prompt or user-facing disclosure at the point of transmission. Although the argument help names the token, the code does not clearly warn that a sensitive credential will be sent off-host to the API.
The section says users asking where to obtain an API key should be told to get it themselves from https://max-studio.shop, but later the same document says integrators should contact the technical team to be issued an API key. These instructions conflict about the intended source of credentials, which can mislead users and integrators about the authentication flow.
The dependency manifest specifies requests without a version constraint, which makes builds non-reproducible and can cause the environment to resolve to a vulnerable or incompatible release. In a skill that performs API calls, uploads, polling, and media downloads, this increases supply-chain and maintenance risk because security posture depends on whatever version gets installed at deployment time.
requests
requests has multiple known advisories, and because the manifest does not pin a version, it is impossible to verify whether installation will select an affected release. This is more concerning in this skill's context because it relies on outbound HTTP interactions and media downloads, where library flaws could contribute to credential leakage, TLS/verification issues, or unsafe request handling.
No suspicious patterns detected.