Back to skill

Security audit

Byted Kickart Subtitle Extractor

Security checks for vulnerabilities and agentic risk

Overview

This subtitle extraction skill has a plausible purpose, but it asks for cloud credentials in chat, logs sensitive request data, and can run a server-provided update command.

Review carefully before installing. Use only least-privilege, short-lived credentials; do not paste long-lived AK/SK secrets into chat; avoid running the self-update path; and treat local logs under /tmp/openclaw as potentially sensitive because they may contain authorization headers, request data, response data, and media metadata.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (5)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:75
Finding

Server-Controlled Update Command Can Be Executed Locally

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/core/api/iccp/client.py:124
Finding

Cloud Credentials Are Exposed in Chat, Command Output, and Persistent Logs

Content
View full analysis
>> {method.upper()} {url} {headers} {body}") response = requests.request( method=method.upper(), url=url, headers=headers, data=body, timeout=30 ) ``` The bearer-token client has the same issue: ```python headers["Authorization"] = f"Bearer {self.token}" headers["Content-Type"] = "application/json" headers["ServiceName"] = self.SERVICE if ppe_env := os.getenv("X_VOLC_ENV"): headers.update( {"X-TT-Env": "ppe_volcengine", "X-Volc-Env": ppe_env, "X-Use-Ppe": "1"} ) logging.info(f">>> {method.upper()} {url} {headers} {body}") response = requests.request( method=method.upper(), url=url, headers=headers, data=body, timeout=30 ) ``` The media client also logs complete headers: ```python url = self.build_url(self.host, action, extra_query) query_string = urlparse(url).query headers = self.build_headers( service, self.host, query_string, payload_hash, is_binary=False ) logging.info( f"[http] <<< {headers} {json.dumps(body or {}, ...[truncated 2500 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/core/api/meida/chunks.py:168
Finding

Environment-Controlled API Destination Can Receive Bearer Tokens and Video Data

Content
View full analysis
Dict[str, str]: return { "ServiceName": service, "Authorization": f"Bearer {self.token}", "Content-Type": "application/octet-stream" if is_binary else "application/json", } def build_url(self, host: str, action: str, extra_query: dict) -> str: url = f"{host}/?Action={action}&Version={AppConfig.VERSION}" if extra_query: url += "&" + urlencode(extra_query) return url ``` The ICCP client behaves similarly: ```python def __init__(self): self.addr = os.getenv("ARK_SKILL_API_BASE") self.token = os.getenv("ARK_SKILL_API_KEY") or "" def do_request(self, method: str, queries: dict, body: bytes, action: str) -> dict: queries["Action"] = action queries["Version"] = self.VERSION query_string = urlencode(queries).replace("+", "%20") url = f"{self.addr}?{query_string}" headers = defaultdict(str) headers["Authorization"] = f"Bearer {self.token}" headers["Content-Type"] = "application/json" headers["ServiceName"] = self.SERVICE ``` ### Technical Analysis No validation constrains `ARK_SKILL_API_BASE` to HTTPS or an expected Volcengine hostname. The destination is used for both task requests and binary media upload opera ...[truncated 1594 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/core/api/meida/chunks.py:286
Finding

Video Upload Unnecessarily Enumerates All Account Users

Content
View full analysis
int: result = self.client.request( action="ListUsers", service=AppConfig.SERVICE_IAM, body={"UserType": "All"} ) users = result.get("Result", {}).get("Users", []) if not users: print("❌ ListUsers returned no users") sys.exit(1) for user in users: if user.get("IsAdmin") and user.get("Id"): return user.get("Id") return users[0].get("Id") ``` The upload process invokes this enumeration before uploading the selected file: ```python def upload(self, file_path: str) -> Any: owner_id = self.uploader.iam.get_admin_user_id() file_md5, file_crc32, file_size = HashUtils.file_hash(file_path) ``` ### Technical Analysis Uploading a user-selected video should not ordinarily require organization-wide user enumeration or discovery of an administrator account. The implementation invokes `ListUsers` with `UserType: All`, processes the resulting roster, and chooses an administrator as the media owner. If no administrator is found, it silently falls back to the first returned user. This design exceeds least privilege and can assign media to an identity other than the authenticated caller. It also forces credentials to possess broader IAM visibility than is necessary for subtitle extraction. ### Attack Path 1. A user invokes the normal video upload command. 2. Before uploading the video, the Skill calls the account-wide `ListUsers` API. 3. The service returns user identifiers and admini ...[truncated 788 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/requirements.txt:1
Finding

Mandatory Runtime Installation Uses Mutable, Unhashed Dependencies

Content
View full analysis
=2.31.0 qrcode>=8.2 jsonpath>=0.82.2 Pillow>=10.1.0 urllib3>=2.1.0 pydantic==2.12.5 pandas==2.3.3 python-dotenv>=1.1.1 click>=8.3.2 ``` ### Technical Analysis Eight of the nine dependencies are not pinned to an exact reviewed version, and none include cryptographic hashes. Every normal Skill invocation is instructed to run `pip install`, allowing dependency resolution to change after the Skill package has been audited. Python packages can execute code during build and installation, and imported packages execute module initialization code at runtime. A compromised package release, package-index compromise, malicious mirror, or unexpected future version could therefore execute in the Agent environment. Some listed packages, such as `qrcode`, also do not appear necessary for the narrow subtitle extraction entry path, unnecessarily increasing the supply-chain attack surface. ### Attack Path 1. A dependency publisher account, package release, configured package index, or network package source is compromised. 2. A new package version satisfying a `>=` constraint is published. 3. The mandatory preflight workflow runs `pip install`. 4. `pip` resolves the mutable dependency to the compromised version. 5. Malicious build, installation, or import-time code executes with Agent process privileges. 6. The malicious dependency accesses environment credentials, local files, video content, or network resources. ### Impact Assessment Successful exploitation can provide arbitrary code execution with the privile ...[truncated 329 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (89)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly instructs the agent to ask users to paste Volcengine ACCESS_KEY_ID and SECRET_ACCESS_KEY into chat, then exports and reuses them. Soliciting raw cloud credentials in a conversational channel is highly dangerous because it enables credential theft, accidental logging, replay, and broader compromise of the user's cloud account.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The instructions tell the agent to have users send AK/SK directly in chat and do not provide a strong warning against sharing secrets in chat. This normalizes insecure secret handling and substantially increases the chance of credential exposure in logs, transcripts, or downstream systems.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill not only requests cloud access keys in chat but also instructs the agent to export them into environment variables and reuse them for subsequent commands. This creates a direct path from conversational input to privileged command execution, magnifying the blast radius of any leak or misuse.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
python3.12 -m pip install -r ./scripts/requirements.txt

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill includes a self-upgrade path that executes an install_command returned by a remote source after asking the user. Remote-controlled installation during skill execution is a supply-chain risk and can lead to arbitrary code execution if the update channel is compromised or the command is malicious.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code logs full request metadata including headers and body before the request, which includes Authorization credentials in both the AK/SK signature flow and Bearer token flow, and may also include sensitive request payloads. It also logs full response headers and body, potentially exposing returned secrets or user data to application logs, which are often widely accessible and retained for long periods.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill calls IAM ListUsers and explicitly searches for an admin account ID, then falls back to the first user if no admin is found. For a subtitle-extraction skill, enumerating users and selecting an elevated owner context is unnecessary and dangerous because it broadens access scope and can cause media operations to run under a privileged identity unrelated to the requesting user.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code implements remote media upload, remote material creation, and polling for uploaded asset metadata, which materially exceeds a subtitle-extraction skill’s declared purpose. In the context of a skill that should only extract subtitles, adding a general upload pipeline creates unnecessary data exfiltration and capability expansion risk, especially because arbitrary local media files are transmitted to a remote service.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The uploader is general-purpose and supports arbitrary image and video asset upload, with no evident restriction tying it to subtitle extraction. That broad capability meaningfully increases the attack surface because the skill can move unrelated local files to a remote platform and manage them as reusable materials, which is dangerous in a narrowly scoped media-processing skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.