Back to skill

Security audit

Byted Kickart Viral Replicator

Security checks for vulnerabilities and agentic risk

Overview

The skill has a real video-generation workflow, but it handles cloud credentials and local files in unsafe, under-scoped ways that users should review carefully before installing.

Do not install this version unless you are comfortable reviewing and fixing its credential handling first. Use only short-lived, least-privilege Volcengine credentials, do not paste long-lived AK/SK secrets into chat, and assume existing logs under /tmp/openclaw/byted-kickart-viral-replicator/logs may contain sensitive Authorization data if the skill has already run. The dynamic update command, detached polling process, and broad local media cache should be tightened before normal use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/core/api/meida/chunks.py:96
Finding

Authentication Credentials Are Written to Persistent Log Files

Content
View full analysis

Vulnerability Details

File Location: scripts/core/api/meida/chunks.py:96-107, with persistent logging configured in scripts/core/__init__.py:53-63
Vulnerability Type: Sensitive credential exposure through logging
Risk Level: High

Vulnerable Code

python
def request(self, action: str, service: str, body: dict = None, extra_query: dict = None) -> dict:
    extra_query = extra_query or {}
    body_bytes = json.dumps(body or {}, ensure_ascii=False).encode()
    payload_hash = HashUtils.hash_sha256(body_bytes).hex()

    url = self.build_url(self.host, action, extra_query)
    query_string = urlparse(url).query
    headers = self.build_headers(
        service, self.host, query_string, payload_hash, is_binary=False
    )

    logging.info(
        f"[http] <<< {headers} "
        f"{json.dumps(body or {}, ensure_ascii=False)}"
    )
    resp = requests.post(url, data=body_bytes, headers=headers, timeout=30)
    logging.info(f"[http] <<< {resp.headers} {resp.text}")

The logged headers contain one of the following authorization values:

python
headers["Authorization"] = f"Bearer {self.token}"

or:

python
authorization = (
    f"HMAC-SHA256 Credential={self.ak}/{credential_scope},"
    f" SignedHeaders={';'.join(signed_headers)},"
    f" Signature={signature}"
)
headers["Authorization"] = authorization

Logging is persistently directed to a predictable file:

python
log_dir = "/tmp/openclaw/byted-kickart-viral-replicator/logs"
os.makedirs(log_dir, exist_ok=True)

logging.basicConfig(
    level=logging.INFO,
    filename=f'{log_dir}/info.{time.strftime("%Y%m%d", time.localtime())}.log',
    format="%(asctime)s - %(levelname)s - %(message)s",
    datefmt="%Y-%m-%d %H:%M:%S",
)

Technical Analysis

Every non-binary API request logs the complete HTTP header dictionary before transmission. In bearer-token mode, this exposes the complete ARK_SKILL_API_KEY. In AK/SK mode, it exposes the Access Key ID, credential scope ...[truncated 1855 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove authorization headers from all logs.
  2. Introduce a centralized redaction function that masks at least:
    • Authorization
    • ARK_SKILL_API_KEY
    • ACCESS_KEY_ID
    • SECRET_ACCESS_KEY
    • Signed URLs and session identifiers
  3. Do not log complete request or response bodies at INFO level. Log only action names, status codes, request IDs, durations, and redacted error summaries.
  4. If diagnostic payload logging is indispensable, require an explicit debug opt-in and recursively redact sensitive fields.
  5. Create the log directory and files with restrictive permissions, such as directory mode 0700 and file mode 0600.
  6. Add rotation, short retention, and secure deletion.
  7. Revoke and rotate any credentials used while vulnerable logging was enabled.
  8. Add automated tests asserting that tokens and authorization headers never appear in captured logs.

T09 · Insecure Skill Coding Practices

Error
Location
references/火山鉴权指南.md:7
Finding

Mandatory Authentication Instructions Expose Full Secrets in Chat and Command Output

Content
View full analysis

Vulnerability Details

File Location: references/火山鉴权指南.md:7-30
Vulnerability Type: Plaintext credential collection and disclosure
Risk Level: High

Vulnerable Instructions

bash
echo "ARK_SKILL_API_BASE: $ARK_SKILL_API_BASE" && echo "ARK_SKILL_API_KEY: $ARK_SKILL_API_KEY" && echo "ACCESS_KEY_ID: $ACCESS_KEY_ID" && echo "SECRET_ACCESS_KEY: $SECRET_ACCESS_KEY"

The guide also instructs the Agent to request credentials directly in chat and interpolate them into shell commands:

text
Directly send your Access Key ID and Secret Access Key here, and I will
configure temporary environment variables for you.
bash
export ACCESS_KEY_ID=<user-provided ACCESS_KEY_ID>
export SECRET_ACCESS_KEY=<user-provided SECRET_ACCESS_KEY>

The same document later states that the values must not be disclosed or persistently stored, but the earlier mandatory steps directly expose them to chat and command-output handling.

Technical Analysis

The prescribed environment check prints four complete authentication-related values, including the bearer token and Secret Access Key. Tool output can become part of the Agent transcript, execution logs, observability systems, debugging records, or platform audit records.

Requesting secrets through ordinary chat similarly places them in systems that may retain conversation history. This conflicts with the document's claim that credentials are only temporarily configured and are not persistently stored.

Interpolating secrets into shell commands also creates avoidable exposure risks through command-history capture, shell tracing, process instrumentation, or logging of executed commands.

Authentication is necessary for the Skill, but displaying secrets and collecting them through ordinary conversational text are not necessary.

Attack Path

  1. The Skill forces authentication validation before normal operations.
  2. The Agent follows the guide and executes the supplied echo command.
  3. Full bearer-toke ...[truncated 861 chars]
Remediation
View remediation

Remediation Suggestions

  1. Never print secret environment-variable values. Check only whether they are present:
bash
test -n "$ARK_SKILL_API_KEY" && echo "ARK_SKILL_API_KEY is configured"
test -n "$ACCESS_KEY_ID" && echo "ACCESS_KEY_ID is configured"
test -n "$SECRET_ACCESS_KEY" && echo "SECRET_ACCESS_KEY is configured"
  1. Do not ask users to paste long-lived credentials into ordinary chat.
  2. Use a dedicated secret-input interface, operating-system keychain, protected credential file, workload identity, or platform secret manager.
  3. Prefer short-lived, narrowly scoped credentials over permanent AK/SK pairs.
  4. If shell environment configuration is unavoidable, pass values through a protected secret channel rather than literal command text.
  5. Ensure command tracing and command logging are disabled around secret handling.
  6. Update the guide so its operational steps are consistent with its stated non-disclosure policy.
  7. Rotate credentials that may already have appeared in conversations or tool output.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/core/api/meida/media.py:141
Finding

Unsanitized Media Identifiers Enable Path Traversal and Arbitrary JSON File Access

Content
View full analysis

Vulnerability Details

File Location: scripts/core/api/meida/media.py:141-166, reachable through scripts/core/api/meida/media.py:284-295 and scripts/replication.py:40-57
Vulnerability Type: Directory traversal
Risk Level: High

Vulnerable Code

python
class SimpleMediaRepository:
    def __init__(self, base_dir: str = None):
        self.base_dir = Path(base_dir or MediaConfig.STORAGE_BASE_DIR)
        self.base_dir.mkdir(parents=True, exist_ok=True)

    def _get_path(self, media_id: str) -> Path:
        """Get media cache file path."""
        return self.base_dir / f"{media_id}.json"

    def load(self, media_id: str) -> dict | None:
        """Load cached data for a media ID."""
        path = self._get_path(media_id)
        if not path.exists():
            raise FileNotFoundError(f"File does not exist: {path}")
        with open(path, 'r', encoding='utf-8') as f:
            return json.load(f)

    def save(self, media_id: str, data: dict):
        path = self._get_path(media_id)
        os.makedirs(path.parent, exist_ok=True)
        with open(path, 'w', encoding='utf-8') as f:
            json.dump(data, f, ensure_ascii=False, indent=2)

    def clear(self, media_id: str):
        path = self._get_path(media_id)
        if path.exists():
            os.remove(path)

The service passes identifiers directly into the repository:

python
def get_media(self, media_id: str) -> dict:
    return self.repository.load(media_id)

A CLI-controlled reference identifier reaches this method:

python
@click.option("--ref-video", required=True, type=str, help="Reference video media ID")
...
video_mat = media_service.get_media(ref_video)

Technical Analysis

_get_path concatenates an unvalidated media identifier with the storage directory and a .json suffix. pathlib does not prevent .. traversal. An identifier such as ../../../target therefore resolves outside the intended media cache.

The load, save, and ...[truncated 2136 chars]

Remediation
View remediation

Remediation Suggestions

  1. Accept only strictly formatted media identifiers, for example:
python
if not re.fullmatch(r"[A-Za-z0-9_-]{1,128}", media_id):
    raise ValueError("Invalid media ID")
  1. Resolve and enforce containment before every filesystem operation:
python
base = self.base_dir.resolve()
candidate = (base / f"{media_id}.json").resolve()

if candidate.parent != base:
    raise ValueError("Media path escapes repository")
  1. Reject path separators, .., absolute paths, null bytes, and platform-specific separator variants.
  2. Apply the validation consistently to _get_path in both SimpleMediaRepository and the grouped MediaRepository.
  3. Do not derive filenames directly from external identifiers. Use a cryptographic digest or an internal database key.
  4. Run the Skill under a dedicated low-privilege operating-system account with access only to required directories.
  5. Add tests for traversal payloads using ../, absolute paths, repeated separators, URL-encoded separators, and Windows path syntax.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/core/utils/downloader.py:194
Finding

Unrestricted URL Downloader Permits Server-Side Request Forgery and Resource Exhaustion

Content
View full analysis

Vulnerability Details

File Location: scripts/core/utils/downloader.py:194-225
Vulnerability Type: Server-side request forgery and unbounded download
Risk Level: Medium

Vulnerable Code

python
async def _download_single(
    self,
    session: aiohttp.ClientSession,
    url: str
) -> DownloadResult:
    try:
        timeout = aiohttp.ClientTimeout(total=self.timeout)
        async with session.get(url, timeout=timeout) as response:
            if response.status != 200:
                return DownloadResult(
                    url=url,
                    success=False,
                    error=f"HTTP {response.status}"
                )

            filename = self.filename_generator.generate(url)
            file_path = os.path.join(self.output, filename)

            with open(file_path, 'wb') as f:
                async for chunk in response.content.iter_chunked(8192):
                    f.write(chunk)
            file_path = self.filename_generator.modify(file_path)
            logging.info(f"Download succeeded: {url} -> {file_path}")
            return DownloadResult(
                url=url,
                success=True,
                file_path=file_path
            )

Technical Analysis

The downloader performs a request to any supplied URL without validating:

  • The URL scheme
  • The destination hostname
  • Resolved IP addresses
  • Loopback, private, link-local, multicast, or reserved ranges
  • Redirect targets
  • Destination ports
  • Response content type
  • Declared or actual response size

This permits requests from the Skill host to services that may not be reachable by the external requester. Redirects can also be used to pass an initial hostname check unless every redirect destination is independently validated.

The response is streamed to disk with no byte limit. A server can therefore return an arbitrarily large or endless response until the overall timeout is reached, potentially filling the temporary filesystem. ...[truncated 1401 chars]

Remediation
View remediation

Remediation Suggestions

  1. Permit only explicitly required schemes, normally https.
  2. Resolve the destination before connection and reject loopback, private, link-local, multicast, unspecified, and reserved IP ranges for both IPv4 and IPv6.
  3. Revalidate the hostname and resolved address after every redirect, or disable redirects and process them manually.
  4. Maintain an allowlist of approved media hosts where operationally possible.
  5. Reject URLs containing embedded credentials or unexpected ports.
  6. Set maximum response sizes and stop downloading when the limit is exceeded.
  7. Validate Content-Length when present, while still enforcing a streamed byte counter.
  8. Validate MIME type and file signatures before retaining or processing content.
  9. Apply outbound firewall or proxy restrictions so the Skill process cannot access metadata services or internal management networks.
  10. Add SSRF regression tests covering decimal and hexadecimal IP forms, IPv6, DNS rebinding, redirects, and mixed public/private DNS results.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (134)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The detected implementation uploads local files, validates media metadata, and returns material IDs but does not itself perform style imitation, structure analysis, or content generation as claimed. The danger is primarily deceptive scope: users and reviewers may underestimate data movement and overestimate functional safeguards tied to the advertised purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The detected implementation uploads local files, validates media metadata, and returns material IDs but does not itself perform style imitation, structure analysis, or content generation as claimed. The danger is primarily deceptive scope: users and reviewers may underestimate data movement and overestimate functional safeguards tied to the advertised purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The detected implementation uploads local files, validates media metadata, and returns material IDs but does not itself perform style imitation, structure analysis, or content generation as claimed. The danger is primarily deceptive scope: users and reviewers may underestimate data movement and overestimate functional safeguards tied to the advertised purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The detected implementation uploads local files, validates media metadata, and returns material IDs but does not itself perform style imitation, structure analysis, or content generation as claimed. The danger is primarily deceptive scope: users and reviewers may underestimate data movement and overestimate functional safeguards tied to the advertised purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The detected implementation uploads local files, validates media metadata, and returns material IDs but does not itself perform style imitation, structure analysis, or content generation as claimed. The danger is primarily deceptive scope: users and reviewers may underestimate data movement and overestimate functional safeguards tied to the advertised purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The detected implementation uploads local files, validates media metadata, and returns material IDs but does not itself perform style imitation, structure analysis, or content generation as claimed. The danger is primarily deceptive scope: users and reviewers may underestimate data movement and overestimate functional safeguards tied to the advertised purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The detected implementation uploads local files, validates media metadata, and returns material IDs but does not itself perform style imitation, structure analysis, or content generation as claimed. The danger is primarily deceptive scope: users and reviewers may underestimate data movement and overestimate functional safeguards tied to the advertised purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The detected implementation uploads local files, validates media metadata, and returns material IDs but does not itself perform style imitation, structure analysis, or content generation as claimed. The danger is primarily deceptive scope: users and reviewers may underestimate data movement and overestimate functional safeguards tied to the advertised purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The detected implementation uploads local files, validates media metadata, and returns material IDs but does not itself perform style imitation, structure analysis, or content generation as claimed. The danger is primarily deceptive scope: users and reviewers may underestimate data movement and overestimate functional safeguards tied to the advertised purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The detected implementation uploads local files, validates media metadata, and returns material IDs but does not itself perform style imitation, structure analysis, or content generation as claimed. The danger is primarily deceptive scope: users and reviewers may underestimate data movement and overestimate functional safeguards tied to the advertised purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The detected implementation uploads local files, validates media metadata, and returns material IDs but does not itself perform style imitation, structure analysis, or content generation as claimed. The danger is primarily deceptive scope: users and reviewers may underestimate data movement and overestimate functional safeguards tied to the advertised purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The detected implementation uploads local files, validates media metadata, and returns material IDs but does not itself perform style imitation, structure analysis, or content generation as claimed. The danger is primarily deceptive scope: users and reviewers may underestimate data movement and overestimate functional safeguards tied to the advertised purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The detected implementation uploads local files, validates media metadata, and returns material IDs but does not itself perform style imitation, structure analysis, or content generation as claimed. The danger is primarily deceptive scope: users and reviewers may underestimate data movement and overestimate functional safeguards tied to the advertised purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The detected implementation uploads local files, validates media metadata, and returns material IDs but does not itself perform style imitation, structure analysis, or content generation as claimed. The danger is primarily deceptive scope: users and reviewers may underestimate data movement and overestimate functional safeguards tied to the advertised purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The detected implementation uploads local files, validates media metadata, and returns material IDs but does not itself perform style imitation, structure analysis, or content generation as claimed. The danger is primarily deceptive scope: users and reviewers may underestimate data movement and overestimate functional safeguards tied to the advertised purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The detected implementation uploads local files, validates media metadata, and returns material IDs but does not itself perform style imitation, structure analysis, or content generation as claimed. The danger is primarily deceptive scope: users and reviewers may underestimate data movement and overestimate functional safeguards tied to the advertised purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The detected implementation uploads local files, validates media metadata, and returns material IDs but does not itself perform style imitation, structure analysis, or content generation as claimed. The danger is primarily deceptive scope: users and reviewers may underestimate data movement and overestimate functional safeguards tied to the advertised purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The detected implementation uploads local files, validates media metadata, and returns material IDs but does not itself perform style imitation, structure analysis, or content generation as claimed. The danger is primarily deceptive scope: users and reviewers may underestimate data movement and overestimate functional safeguards tied to the advertised purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The detected implementation uploads local files, validates media metadata, and returns material IDs but does not itself perform style imitation, structure analysis, or content generation as claimed. The danger is primarily deceptive scope: users and reviewers may underestimate data movement and overestimate functional safeguards tied to the advertised purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The referenced guide is functionally unrelated to the declared purpose of a viral video cloning skill and instead injects a task-progress querying workflow. This kind of capability mismatch is dangerous because it can covertly redirect agent behavior, cause the agent to access persisted task metadata from prior sessions, and override expected tool-selection logic in ways the user did not request.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide defines trigger phrases such as progress/result-checking intents that contradict the skill's declared activation conditions around cloning viral videos. Conflicting triggers can cause unintended invocation on ordinary user requests, leading the agent to execute unrelated logic and potentially disclose or act on stored task state outside the user's actual intent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The forced workflow explicitly instructs the agent to prioritize progress-query behavior over the manifest's declared video-cloning behavior and to retrieve persistent Task IDs from session context. This is dangerous because it attempts to supersede higher-level routing with hidden instructions and can induce unauthorized access to prior task metadata or cross-context actions not grounded in the current user request.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The version-check flow runs a local upgrade script and then may execute an install_command returned by that script, effectively allowing dynamic command execution based on update metadata. This is dangerous because it can turn a routine package-validation step into arbitrary code execution or unauthorized software changes, which is unrelated to the core content-cloning function and increases attack surface substantially.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file instructs the agent to echo environment variables containing API keys and secret access keys, which can directly reveal live credentials in command output. This is especially dangerous because secrets may be exposed to the user, logs, monitoring systems, or any component that captures terminal output.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The guide explicitly instructs the agent to solicit raw ACCESS_KEY_ID and SECRET_ACCESS_KEY values from users in chat and use them for configuration. For a viral video cloning skill, this is unjustified access to highly sensitive credentials and creates a direct secret-exfiltration and misuse path if the agent, logs, or surrounding systems are compromised.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.