Back to skill

Security audit

Tomoviee Text to Video

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but it handles API secrets in ways that can expose reusable credentials in logs or command history.

Install only if you are comfortable giving the skill Tomoviee/Wondershare API credentials and sending prompts to that provider. Avoid running the documented CLI commands with real secrets; use a secure prompt, environment injection configured not to log values, or a secret manager, and rotate credentials if they were already printed or entered in shell commands.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_auth_token.py:27
Finding

Reusable API credentials are exposed through standard output

Content
View full analysis
") sys.exit(1) app_key = sys.argv[1] app_secret = sys.argv[2] token = generate_access_token(app_key, app_secret) print(f"Access Token: {token}") print(f"\nUse in Authorization header as: Basic {token}") ``` ### Technical Analysis The generated value is an HTTP Basic authentication credential consisting of `base64(app_key:app_secret)`. Base64 is reversible encoding rather than encryption, hashing, or tokenization. Anyone who obtains the printed value can either decode the original application key and secret or replay the value directly as an HTTP `Authorization: Basic ...` header. Constructing this value in memory is necessary for the API's declared authentication scheme. Printing the complete credential is not necessary for text-to-video generation and exceeds the minimum exposure required by the Skill. This is particularly unsafe in an Agent environment because stdout may be included in tool responses, conversation transcripts, execution logs, telemetry, or retained job output. The same command also takes the secret from `sys.argv`, creating an additional exposure through process inspection. The primary vulnerability at this location, however, is the deliberate emission of the reusable credential to stdout. ### Attack Path 1. A user or Agent follows the documented authentication workflow and invokes the token generator with valid API credentials. 2. The script constructs the reversible Basic authentication value. 3. The complete reusable credential is pr ...[truncated 1047 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/tomoviee_text2video_client.py:142
Finding

Application secrets are exposed through client command-line arguments

Content
View full analysis
[resolution] [aspect_ratio]" ) sys.exit(1) app_key = sys.argv[1] app_secret = sys.argv[2] prompt = sys.argv[3] resolution = sys.argv[4] if len(sys.argv) > 4 else "720p" aspect_ratio = sys.argv[5] if len(sys.argv) > 5 else "16:9" client = TomovieeText2VideoClient(app_key, app_secret) ``` ### Technical Analysis The direct-execution interface requires users to place the application secret in the process argument vector. On many operating systems, process arguments can be inspected by other local users or monitoring services while the process runs. They may also be retained in shell history, command auditing, process telemetry, CI logs, Agent transcripts, or orchestration metadata. The client legitimately needs credentials to authenticate with the declared HTTPS gateway. It does not need to receive the secret through a publicly observable argument. The internal Base64 conversion and transmission to the fixed `https://openapi.wondershare.cc` endpoints are consistent with the declared HTTP Basic authentication workflow; the insecure behavior is the CLI secret-delivery mechanism. ### Attack Path 1. A user or automation system invokes the client as documented, placing a valid application secret in the command line. 2. The operating system and invoking environment expose or retain the complete argument vector. 3. A local user, monitoring integration, CI viewer, Agent transcript reader, or party with access to shell history captures the secret. 4. The attacker combines the exposed secret with the accompanying application key. 5. The attacker generates the corresponding Basic authentication ...[truncated 609 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says this skill creates 5-second videos from text prompts through a specific API gateway and model. The supplied code only constructs and prints a Basic auth token from provided credentials. While token generation could be a supporting utility for later API access, this code chunk by itself does not perform the described primary function and lacks any video-generation logic, API requests, prompt handling, or media parameter controls. Therefore the description does not accurately represent this code chunk’s actual behavior.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/generate_auth_token.py (reported line 18)May include surrounding context.

python
def generate_access_token(app_key: str, app_secret: str) -> str:
    """
    Generate access token for Tomoviee API authentication.
    
    Args:
        app_key: Application key from Tomoviee console

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/tomoviee_text2video_client.py (reported line 29)May include surrounding context.

python
def generate_access_token(app_key: str, app_secret: str) -> str:
    """
    Generate access token for Tomoviee API authentication.
    
    Args:
        app_key: Application key from Tomoviee console

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The script prints the generated Basic authentication token directly to stdout. Because the token is just base64-encoded app_key:app_secret, anyone who sees logs, terminal scrollback, copied output, or CI artifacts can recover the underlying credentials and use the API as that application.

Content

Scanner excerpt · scripts/generate_auth_token.py (reported line 41)May include surrounding context.

python
app_secret = sys.argv[2]
    
    token = generate_access_token(app_key, app_secret)
    print(f"Access Token: {token}")
    print(f"\nUse in Authorization header as: Basic {token}")

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documents network-based behavior and external API usage, but it does not declare any explicit tool scope such as allowed network permissions. That creates a policy and review gap: a consumer or runtime may not have clear constraints on outbound connectivity, making unauthorized or unexpected network access harder to detect and govern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script instructs users to pass the application secret as a command-line argument, which can expose the secret through shell history, process listings, audit logs, and CI job output. Even though the script is a simple helper, this handling pattern increases the chance of credential disclosure on multi-user systems or shared environments.

Content

No source excerpt is available for this finding.

Tainted flow: 'task_id' from requests.post (line 62, network input) → requests.post (network output)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/tomoviee_text2video_client.py (reported line 96)May include surrounding context.

python
def get_result(self, task_id: str) -> Dict[str, Any]:
        """Get task result."""
        response = requests.post(
            self.RESULT_ENDPOINT,
            headers=self._get_headers(),
            json={"task_id": task_id},

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The usage examples show prompts only in Chinese (猫咪转头看向镜头, 女孩突然转头...) in a general reference file, which can imply that users should use a specific language. The file does not state that Chinese is optional, nor does it justify a Chinese-only locale requirement.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
89% confidence
Finding

The dependency specification allows any requests version from 2.31.0 up to, but not including, 3.0.0, which means installation may resolve to releases with known security advisories unless a separate lockfile constrains it. Because the manifest alone does not prove a safe patched version will be used, this creates supply-chain uncertainty and can expose the skill to known flaws in HTTP handling, credential leakage, or related client-side issues.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.