Back to skill

Security audit

Tomoviee Text to Music

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its text-to-music purpose, but it can expose Tomoviee API credentials and includes guidance for unrelated media APIs.

Review before installing. Use this only for text-to-music requests and assume prompts and credentials are sent to Wondershare/Tomoviee. Avoid the documented auth-token helper and avoid passing secrets on the command line; use a secret manager, protected environment variables, or an interactive secret prompt instead. Rotate Tomoviee credentials if they were already run through the helper in an agent, terminal, CI, or logged environment.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_auth_token.py:26
Finding

Reversible API Credentials Exposed Through Command-Line Arguments and Standard Output

Content
View full analysis

Vulnerability Details

File Location: scripts/generate_auth_token.py:26-29, 31-38
Vulnerability Type: Credential exposure through reversible encoding and insecure output
Risk Level: High

Vulnerable Code

python
credentials = f"{app_key}:{app_secret}"
access_token = base64.b64encode(credentials.encode()).decode()
return access_token


if __name__ == "__main__":
    if len(sys.argv) != 3:
        print("Usage: python generate_auth_token.py <app_key> <app_secret>")
        sys.exit(1)
    
    app_key = sys.argv[1]
    app_secret = sys.argv[2]
    
    token = generate_access_token(app_key, app_secret)
    print(f"Access Token: {token}")
    print(f"\nUse in Authorization header as: Basic {token}")

The vulnerable execution pattern is explicitly documented in SKILL.md:37-41:

bash
python scripts/generate_auth_token.py YOUR_APP_KEY YOUR_APP_SECRET

Technical Analysis

HTTP Basic authentication uses Base64 as a transport encoding, not as encryption. The generated token can be decoded directly to recover the original app_key:app_secret value.

The helper prints this reversible credential representation to standard output. In an AI Agent context, standard output may be returned to the caller or retained in execution transcripts and logs. The documented invocation also passes the application secret through a command-line argument, which may expose it through shell history, process inspection, command auditing, or orchestration logs.

Although constructing a Basic Authorization header is necessary for the declared API functionality, exposing that token through a standalone helper is not necessary. The main client already generates and applies the header internally.

Attack Path

  1. A user or Agent follows the command documented in SKILL.md.
  2. The application key and secret are supplied as process arguments.
  3. The helper concatenates the credentials and Base6 ...[truncated 1038 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the helper's token-printing behavior and delete the documented command that encourages users to expose credentials.
  2. Keep Basic token construction internal to the API client and never log or return authentication headers to Agent-visible output.
  3. Do not accept secrets through command-line arguments. Use a secret manager, protected environment injection, or interactive input through getpass.getpass().
  4. If a diagnostic helper must remain, make it perform a connectivity check without displaying the token or secret.
  5. Add centralized redaction for Authorization, app_secret, and Base64-encoded credential values in application, Agent, CI, and HTTP-debug logs.
  6. Update SKILL.md to recommend secure secret injection and warn that Basic tokens are equivalent to the underlying credentials.
  7. Rotate any credentials that have already been processed by this helper in logged or Agent-mediated environments.
  8. Add automated tests that capture stdout and assert that neither raw credentials nor their Base64 representation is emitted.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This is a material description-behavior mismatch. The declared purpose says the skill generates background music from text prompts using a specific API endpoint. However, the code chunk is a standalone utility that encodes credentials into a Basic auth token for later API authentication. While authentication could be a supporting implementation detail in a larger system, this chunk by itself does not implement the declared user-facing capability and instead has a different immediate purpose: credential preparation.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
- Do not commit credentials into `SKILL.md`, scripts, or repository files.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/generate_auth_token.py (reported line 18)May include surrounding context.

python
def generate_access_token(app_key: str, app_secret: str) -> str:
    """
    Generate access token for Tomoviee API authentication.
    
    Args:
        app_key: Application key from Tomoviee console

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Printing the generated Basic authorization token exposes reusable credentials to anyone with access to terminal output, logs, captured CI artifacts, or screen recordings. Because Basic auth here is just base64-encoded key and secret, disclosure of the token effectively discloses the underlying credentials and can enable unauthorized API use.

Content

Scanner excerpt · scripts/generate_auth_token.py (reported line 41)May include surrounding context.

python
app_secret = sys.argv[2]
    
    token = generate_access_token(app_key, app_secret)
    print(f"Access Token: {token}")
    print(f"\nUse in Authorization header as: Basic {token}")

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill documents outbound API usage to external hosts but does not declare any explicit tool scope such as network permissions or allowed domains. This weakens platform-level containment and review because a runtime with broader default network access could contact unintended endpoints without a clear policy boundary. In this context, the risk is elevated because the skill handles API credentials and is intended to make authenticated external requests.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The prompt guide is presented as a skill reference for a text-to-music integration, but it advertises broader Tomoviee API capabilities beyond that declared scope. In an agent setting, this can mislead downstream systems or users into invoking unrelated media-generation workflows, expanding the skill’s effective permissions and increasing the chance of unauthorized or unsafe tool use.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file extensively documents video, image, speech, soundtrack, and chaining workflows unrelated to the declared text-to-music skill. Such overbroad instructions can act as capability smuggling: an LLM agent may infer it is allowed to help with or orchestrate unrelated generation APIs, potentially causing policy bypass, unexpected data flow between tools, or execution outside the intended trust boundary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script requires secrets to be passed as command-line arguments and then prints the derived Basic auth token to stdout. Command-line arguments can be exposed via shell history, process listings, CI logs, and terminal recording, so this creates a real credential-handling weakness even though the script's purpose is authentication setup.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code posts user-supplied prompt data and authentication material to a remote API, but the client methods themselves provide no confirmation, warning, or explanatory comment about that transmission. For code files, outbound network calls carrying user or system data should have some form of disclosure unless clearly surfaced elsewhere; the module docstrings here do not warn that prompts and credentials are sent to an external service.

Content

No source excerpt is available for this finding.

Tainted flow: 'task_id' from requests.post (line 55, network input) → requests.post (network output)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/tomoviee_text2music_client.py (reported line 90)May include surrounding context.

python
return self._make_request(payload)

    def get_result(self, task_id: str) -> Dict[str, Any]:
        response = requests.post(
            self.RESULT_ENDPOINT,
            headers=self._get_headers(),
            json={"task_id": task_id},

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency is only constrained to a broad major-version range and not pinned to a specific vetted release, so the actual installed version can vary across environments and may resolve to a release with known security advisories. In a network-facing skill that calls an external API, using an unpinned HTTP client library increases supply-chain uncertainty and can expose the skill to credential leakage, request handling flaws, or other known issues present in older requests versions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.