Back to skill

Security audit

Byted Kickart Video Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This video-analysis skill has review-worthy risk because it asks for cloud credentials in chat, exposes secrets in output/logs, and can run a server-supplied update command.

Install only if you are comfortable sending videos to the external Volcengine/Ark service and can provide tightly scoped, disposable credentials through a secure mechanism. Do not paste long-lived AK/SK values into chat, rotate any keys previously used with this workflow, and avoid approving remote update commands unless the publisher provides a verified package source and integrity checks.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (6)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:81
Finding

Execution of an Unrestricted Remote-Supplied Upgrade Command

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/core/api/iccp/client.py:91
Finding

Authentication Tokens and Request Data Persisted in Plaintext Logs

Content
View full analysis
>> {method.upper()} {url} {headers} {body}") response = requests.request(method=method.upper(), url=url, headers=headers, data=body, timeout=30) logging.info(f"<<< {response.headers} {response.text}") ``` Bearer tokens are also logged: ```python headers = defaultdict(str) headers["Authorization"] = f"Bearer {self.token}" headers["Content-Type"] = "application/json" headers["ServiceName"] = V2IccpClient.SERVICE if ppe_env := os.getenv("X_VOLC_ENV"): headers.update({"X-TT-Env": "ppe_volcengine", "X-Volc-Env": ppe_env, "X-Use-Ppe": "1"}) logging.info(f">>> {method.upper()} {url} {headers} {body}") response = requests.request(method=method.upper(), url=url, headers=headers, data=body, timeout=30) logging.info(f"<<< {response.headers} {response.text}") ``` The media client similarly records complete headers and bodies: ```python headers = self.build_headers(service, self.host, query_string, payload_hash, is_binary=False) logging.info(f"[http] <<< {headers} {json.dumps(body or {}, ensure_ascii=False)}") resp = requests.post(url, data=body_bytes, headers=headers, timeout=30) lo ...[truncated 1842 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:41
Finding

Long-Lived Cloud Credentials Exposed Through Chat and Shell Output

Content
View full analysis
export SECRET_ACCESS_KEY= ``` 3. Tell the user that the temporary configuration applies only to the current session. ``` ### Technical Analysis The mandatory preflight check prints complete credentials rather than checking only whether variables are set. The instructions also request that users paste long-lived AK/SK credentials directly into chat. Secrets supplied this way may be retained in conversation history, Agent transcripts, tool-call records, shell history, terminal capture, telemetry, or debugging output. Exporting the values only for the current shell does not remove copies already retained by these surrounding systems. Printing `SECRET_ACCESS_KEY` is not necessary for authentication validation and violates least-exposure principles. ### Attack Path 1. Authentication variables are absent. 2. The Skill instructs the user to provide AK/SK credentials in chat. 3. The credentials become part of the conversation record. 4. The Agent exports the values into its process environment. 5. The mandatory `echo` command prints all credential values into command output. 6. Anyone with access to the transcript, tool output, or captured terminal data can recover the credentials. 7. The attacker uses the credentials to sign API requests within their IAM scope. ## ...[truncated 354 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/core/api/meida/chunks.py:234
Finding

Account-Wide IAM Enumeration and Administrator Ownership for Media Uploads

Content
View full analysis
int: result = self.client.request(action="ListUsers", service=AppConfig.SERVICE_IAM, body={"UserType": "All"}) users = result.get("Result", {}).get("Users", []) if not users: print("❌ 未获取到任何用户信息") sys.exit(1) for user in users: if user.get("IsAdmin") and user.get("Id"): return user.get("Id") return users[0].get("Id") ``` Every upload invokes this behavior: ```python def upload(self, file_path: str) -> Any: owner_id = self.uploader.iam.get_admin_user_id() file_md5, file_crc32, file_size = HashUtils.file_hash(file_path) file_name = os.path.splitext(os.path.basename(file_path))[0] file_ext = os.path.splitext(file_path)[1].lstrip(".") cat = "image" if file_ext.lower() in AppConfig.IMAGE_EXTENSIONS else "video" title = f"artclaw-material-{int(time.time())}" owner_type = "user" state = self.uploader.muse.get_upload_state(file_md5, file_size, file_crc32, owner_id) ``` ### Technical Analysis Uploading and analyzing one user-selected video does not inherently require listing every user in the cloud account or selecting an administrator as the media owner. This design expands the required IAM permissions from media-specific operations to account-wide identity discovery. It also associates uploaded material with an elevated account identity rather than the authenticated principal or a dedicated least-privilege service account. The fallback to the first returned user is amb ...[truncated 856 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:121
Finding

Server-Side Request Forgery Risk in User-Controlled Video Download

Content
View full analysis
" ``` Check whether the file exists: ```bash ls -la /tmp/openclaw/byted-kickart-video-analyzer/input/downloaded_video.mp4 ``` ``` ### Technical Analysis The Agent is instructed to pass a user-controlled URL to `curl -L`. Quoting the URL prevents ordinary shell metacharacter expansion but does not prevent server-side request forgery. There is no enforcement of: - HTTPS-only transport. - Approved destination domains. - Rejection of localhost, private, link-local, multicast, or reserved addresses. - DNS rebinding protection. - Redirect target validation. - Connection or total timeout. - Maximum download size. - Response content-type restrictions before writing the body. Because `-L` follows redirects, an initially public URL can redirect to an internal address. The subsequent file-format check occurs only after the request has already reached the target and downloaded its response. ### Attack Path 1. An attacker supplies a URL that resolves to an internal service, localhost, a link-local metadata endpoint, or an attacker-controlled redirector. 2. The Agent executes the documented `curl -L` command. 3. The runtime sends a request from its trusted network environment. 4. A redirect can lead the request to a private or otherwise prohibited destination. 5. The response is written to the Skill's input directory. 6. Observable status, timing, size, or later file handling may disclose information about the internal target; a large response may also exhaust disk or bandwidth. ### Impact Assessment The behavior can be used to probe services reachable ...[truncated 236 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/requirements.txt:1
Finding

Mandatory Installation of Unpinned Dependencies Without Integrity Verification

Content
View full analysis
=2.31.0 qrcode>=8.2 jsonpath>=0.82.2 Pillow>=10.1.0 urllib3>=2.1.0 pydantic==2.12.5 pandas==2.3.3 python-dotenv>=1.1.1 click>=8.3.2 ``` The Skill mandates installation from the runtime's configured package source: ```bash python3.12 -m pip install -r ./scripts/requirements.txt ``` ### Technical Analysis Eight of the nine dependencies use lower-bound constraints, allowing future versions that were not present during review. No lockfile, package hash, signature verification, or approved package-index configuration is supplied. Python package installation can execute package build backends and installation-related code. Consequently, compromise of a package, its maintainer account, a transitive dependency, or the configured package index can introduce executable code into the runtime. Some declared packages are not evidently required for the main video upload and analysis path, further increasing the dependency and attack surface. ### Attack Path 1. The mandatory preflight process runs `pip install`. 2. The resolver contacts the environment's configured package index. 3. It selects any version satisfying the broad `>=` constraints, including versions released after the audit. 4. A compromised or malicious package or transitive dependency is downloaded. 5. Package build or import behavior executes attacker-controlled code. 6. That code runs with access to the Skill process's files, environment variables, credentials, and network permissions. ### Impact Assessment A successful supply-chain compromise can result in arbitrary code execution with the Agent runtime's privileges. This may expose Volcengine credentials, uploaded media, generated ana ...[truncated 183 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (80)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The workflow centers on uploading local media to an external service under the banner of video parsing, but the description does not make that trust boundary explicit. This is dangerous because local files may contain sensitive content, and users may not understand that data leaves the local environment and is processed remotely.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The workflow centers on uploading local media to an external service under the banner of video parsing, but the description does not make that trust boundary explicit. This is dangerous because local files may contain sensitive content, and users may not understand that data leaves the local environment and is processed remotely.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The workflow centers on uploading local media to an external service under the banner of video parsing, but the description does not make that trust boundary explicit. This is dangerous because local files may contain sensitive content, and users may not understand that data leaves the local environment and is processed remotely.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The workflow centers on uploading local media to an external service under the banner of video parsing, but the description does not make that trust boundary explicit. This is dangerous because local files may contain sensitive content, and users may not understand that data leaves the local environment and is processed remotely.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The workflow centers on uploading local media to an external service under the banner of video parsing, but the description does not make that trust boundary explicit. This is dangerous because local files may contain sensitive content, and users may not understand that data leaves the local environment and is processed remotely.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The workflow centers on uploading local media to an external service under the banner of video parsing, but the description does not make that trust boundary explicit. This is dangerous because local files may contain sensitive content, and users may not understand that data leaves the local environment and is processed remotely.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The workflow centers on uploading local media to an external service under the banner of video parsing, but the description does not make that trust boundary explicit. This is dangerous because local files may contain sensitive content, and users may not understand that data leaves the local environment and is processed remotely.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The workflow centers on uploading local media to an external service under the banner of video parsing, but the description does not make that trust boundary explicit. This is dangerous because local files may contain sensitive content, and users may not understand that data leaves the local environment and is processed remotely.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The workflow centers on uploading local media to an external service under the banner of video parsing, but the description does not make that trust boundary explicit. This is dangerous because local files may contain sensitive content, and users may not understand that data leaves the local environment and is processed remotely.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The workflow centers on uploading local media to an external service under the banner of video parsing, but the description does not make that trust boundary explicit. This is dangerous because local files may contain sensitive content, and users may not understand that data leaves the local environment and is processed remotely.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The workflow centers on uploading local media to an external service under the banner of video parsing, but the description does not make that trust boundary explicit. This is dangerous because local files may contain sensitive content, and users may not understand that data leaves the local environment and is processed remotely.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The workflow centers on uploading local media to an external service under the banner of video parsing, but the description does not make that trust boundary explicit. This is dangerous because local files may contain sensitive content, and users may not understand that data leaves the local environment and is processed remotely.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The workflow centers on uploading local media to an external service under the banner of video parsing, but the description does not make that trust boundary explicit. This is dangerous because local files may contain sensitive content, and users may not understand that data leaves the local environment and is processed remotely.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

The authentication check command explicitly echoes API keys and secret access keys from environment variables. Printing secrets to stdout risks exposure in logs, transcripts, debugging output, and to any downstream observer, creating immediate compromise of cloud credentials.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly instructs the agent to ask users to paste cloud AK/SK credentials into chat and then export them for subsequent commands. This is a direct secret-handling anti-pattern: chat is not an appropriate credential channel, the values may be logged or exposed, and the request is not justified by the stated task of video analysis.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

The skill tells the agent to collect AK/SK secrets directly in chat and reuse them within the session. This enables credential theft, accidental logging, downstream leakage to tools or transcripts, and unauthorized access to the user's cloud account; in the context of a video-analysis skill, it is severely disproportionate and highly suspicious.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The instructions solicit highly sensitive AK/SK credentials and provide no safety warning or secure handling guidance. In this context, the absence of warning is especially dangerous because the skill normalizes secret disclosure for a routine media task, increasing phishing-like risk and credential compromise.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
python3.12 -m pip install -r ./scripts/requirements.txt

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code logs the full request URL, headers, and body immediately before the outbound call. For the AK/SK flow, the Authorization signature and potentially sensitive video-analysis payloads are written to logs, which can expose secrets and user data to anyone with log access.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

The V2 client logs request headers containing a bearer token in the Authorization header. A leaked bearer token can typically be replayed directly to access the remote API, making this a direct credential-exposure issue.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code performs remote upload of local media to a Muse service, including hashing, state negotiation, material creation, and polling for media info, which goes beyond a skill described as local/video analysis and metadata extraction. In a media-analysis skill context, silently transmitting user-provided local files to an external service creates a significant data exfiltration and privacy risk, especially for sensitive videos.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill metadata claims video analysis functionality, but the actual code performs an unrelated network operation to register an 'Ark Claw' package. This deceptive mismatch is dangerous because a user invoking a media-processing skill would instead trigger an external service action they did not request, which could enroll accounts, consume quotas, or grant third-party benefits without informed consent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares no explicit tool scope even though it clearly uses environment access, local file I/O, and network operations. Missing scope declarations weaken review and runtime containment, making it easier for a broadly triggered skill to access secrets and exfiltrate user-provided media without clear user-facing constraints.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger includes vague 'equivalent intent' language, which can cause the skill to activate on loosely related requests. For a skill that accesses files, networks, and credentials, overbroad triggering materially increases the chance of unintended invocation and sensitive action in the wrong context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill description, prompts, and output templates are entirely in Chinese and direct the agent to use fixed Chinese user-facing messages. There is no opt-in, language selection, or documented reason that the skill must operate only in Chinese, which creates a locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.