Back to skill

Security audit

FTK SERCET Minimax H3

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a local fight-storyboarding reference library, but it contains under-disclosed prompt-generation templates and highly detailed real-world combat technique guidance that users should review before installing.

Install only if you are comfortable with a Chinese-language fight-design library that may produce or reuse video-prompt templates despite saying it should not, and that includes detailed martial-arts and weapon choreography. Treat outputs as fictional/staged choreography only, do not use it for real-world fighting advice, and avoid ingesting private files unless you want their content stored in the skill's reusable reference library.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (76)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
The code does not implement the declared primary function of generating combat plots, action chains, or storyboards from user ideas, nor does it ingest user materials into the reference library. Instead, it performs offline integrity validation of routing metadata and related reference files. While metadata maintenance is mentioned in the description, this script only validates existing metadata; it does not maintain, update, compile, or generate prompts/content. Therefore the actual behavior is materially narrower and different from the declared purpose.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
Early in the document, the skill explicitly says it does not generate prompts for any model or platform. However, later sections instruct the agent to output '可直接复制到提示词中的精简动作正文' and provide a dedicated '用户要“视频提示词”' output format with platform-ready structure, which materially expands behavior beyond the stated non-prompt scope.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
This is an active contradiction within the file's own guidance. The prohibition on prompt generation is not merely incomplete; later sections explicitly tell the agent how to produce prompt-ready and platform-conditioned '视频提示词' output, including negative constraints and formatting rules.

Missing User Warnings

High
Confidence
99% confidence
Finding
This file is an extensive operational library of combat techniques, targeting guidance, chaining logic, and strike placement that can directly enable realistic physical violence rather than merely discuss fiction at a high level. The lack of any safety framing, de-escalation boundaries, or abstraction makes it usable as actionable assault choreography and harmful training material, and the skill context amplifies that risk because it is explicitly designed to compile user fighting concepts into structured action plans.

Missing User Warnings

High
Confidence
98% confidence
Finding
This file is a detailed library of combat, joint-destruction, choking, striking, and takedown techniques with execution-level instructions, target anatomy, chaining logic, and follow-up attack guidance. In the context of an agent skill that retrieves and compiles such material for fight scene design, this materially lowers the barrier to generating actionable violent tactics, including techniques aimed at the throat, spine, eyes, joints, and unconsciousness or incapacitation.

Missing User Warnings

High
Confidence
98% confidence
Finding
This file provides highly detailed, execution-level instructions for real-world physical violence, including strike sequencing, targeting of vulnerable body parts such as the throat, jaw, temples, heart/chest center, and eyes, and tactical chaining to defeat defenses. In the context of a skill that ingests, organizes, and retrieves combat references for downstream generation, this materially increases the risk of enabling users to plan or refine harmful assaults rather than merely depicting fictional action.

Missing User Warnings

High
Confidence
95% confidence
Finding
This file provides structured, actionable guidance for controlling, disabling, and finishing an opponent with high-risk striking and grappling techniques, including sequencing, target areas, and 'termination' conditions. Although it contains minor style/use constraints, it lacks meaningful safety, legality, de-escalation, or professional-supervision warnings, and in the context of a skill designed to compile fight choreography and combat action assets, it can facilitate real-world violent misuse rather than purely fictional description.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The file’s declared purpose conflicts with the parent skill metadata: it explicitly instructs the agent to generate direct video prompts and storyboards even though the enclosing skill says it is not responsible for prompt generation. This kind of scope drift is dangerous because downstream orchestration, permissioning, or safety review may rely on the manifest description and therefore invoke this file in contexts where prompt generation was supposed to be disallowed.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The skill file explicitly instructs the agent to output a direct video-generation prompt as its sole deliverable, which conflicts with the manifest’s declared scope that it does not generate prompts. This creates a scope-integrity violation: downstream systems or users may rely on the manifest for safety and capability boundaries, but the embedded instructions override those expectations and can cause the agent to perform higher-risk actions than advertised.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
Declaring the agent’s 'only final deliverable' as a video-model prompt hard-codes behavior that contradicts the stated role of the skill. This is dangerous because it undermines trust boundaries and can bypass orchestration logic, review gates, or user expectations built around the manifest’s narrower, non-prompt-generation function.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The file explicitly defines itself as a prompt template that produces a complete video-generation prompt, which conflicts with the skill metadata claiming it does not generate prompts. This kind of scope mismatch is dangerous because downstream agents, reviewers, or policy gates may trust the manifest and allow behavior they would otherwise restrict or monitor more closely.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
These sections repeatedly instruct the system to output a copyable final prompt/script for target video platforms, confirming operational behavior outside the declared skill scope. The risk is policy evasion through documentation mismatch: systems may route user data, permissions, or safety controls based on the manifest while the embedded file performs more capable prompt-compilation work.

Lp3

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding
Without declared permissions the skill's intent is opaque and cannot be validated.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The skill name/description and all operational instructions are written entirely in Chinese, and there is no statement that the user may choose another language or locale. This can constitute a language/locale policy violation because the skill effectively constrains interaction language without opt-in or documented justification.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
This markdown file is written predominantly in Chinese, including headings and operational descriptions, but it does not indicate that the skill is region-specific or provide any user opt-in for language preference. Under the policy rule for natural-language violations, forcing a specific language without user choice can be a locale-policy issue.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The initial intent statement forbids '模型/平台语法' and '负面词' from entering design or reference outputs. Later, the '视频提示词' section explicitly includes platform-conditioned formatting and '必要的负面约束', directly reversing the earlier instruction.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The reference file explicitly instructs the model to act as an AI video prompt expert and reconstruct user requests into prompt-like scripts, which conflicts with the manifest’s stated scope that the skill does not generate prompts. This kind of instruction drift can cause the agent to exceed its declared capability boundaries, leading to unsafe routing, misleading behavior, or unreviewed prompt-generation output.

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The embedded role definition frames the skill as a prompt-generation expert despite documentation saying it is not responsible for prompt generation. In instruction-following systems, contradictory internal guidance can override higher-level product expectations and cause the model to produce disallowed or unexpected outputs.

Natural-Language Policy Violations

Medium
Confidence
76% confidence
Finding
全文以中文固定编写并以命令式方式规定输出行为,但未说明是否允许根据用户偏好切换语言,也未提供语言选择或 opt-in 机制。按规则,强制特定语言/locale 且无用户选择可构成自然语言政策问题。

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The manifest description is entirely in Chinese and the file contains no indication that language selection is optional or limited to a region-specific use case. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The file’s description and operational instructions are entirely Chinese-language, and there is no natural-language indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The file’s operational description and instructions are entirely in Chinese, and there is no indication that the skill supports other languages or requires Chinese for a region-specific purpose. Under the policy, imposing a specific language without user opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The entire skill file is written in Chinese and provides no indication that language choice is optional or that the skill is intentionally restricted to a Chinese-speaking or region-specific context. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The file presents all instructions, triggers, and constraints exclusively in Chinese, which can impose a language requirement on users without opt-in. Under the stated policy, forcing a specific language is a natural-language policy violation unless the skill offers a language choice or clearly documents a justified region-specific constraint.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The routing rules govern which combat-design reference files the agent may retrieve, and some of the matching guidance is broad enough that ordinary user requests could satisfy multiple routes. In a skill that compiles user ideas into action/storyboard outputs, ambiguous routing can cause over-selection, inconsistent file access, and unintended use of unrelated specialized material, reducing control over prompt/data boundaries.

Static analysis

No suspicious patterns detected.