Back to skill

Security audit

确认后生产

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed media-production runner that requires explicit confirmation before sending project prompts or media to configured providers and saving outputs.

Install only if you intend to run paid media generation through the configured providers. Keep adapter config outside the project, use approved provider URLs and API keys, review each preview before confirming, and avoid sending confidential project content unless those providers are approved for it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
Findings (23)

Tainted flow: 'request' from os.environ.get (line 1371, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/provider_adapters.py (reported line 926)May include surrounding context.

python
if body is not None:
        request.add_header("Content-Type", "application/json")
    try:
        with urllib.request.urlopen(request, timeout=180) as response:
            raw = response.read(MAX_JSON_RESPONSE + 1)
            headers = dict(response.headers.items())
    except urllib.error.HTTPError as exc:

Tainted flow: 'url' from os.environ.get (line 1578, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

_download() fetches a provider-supplied HTTPS URL and only validates that it uses HTTPS and has a non-empty host. Because the download URL is not constrained to an expected host or IP range, a compromised provider response or hostile base-URL configuration could cause server-side requests to arbitrary external or internal endpoints, creating SSRF exposure and pulling attacker-controlled content into the output path.

Content

Scanner excerpt · scripts/provider_adapters.py (reported line 1200)May include surrounding context.

python
path = _output_root(job) / ("result" + Path(target).suffix.casefold())
    size = 0
    try:
        with urllib.request.urlopen(url, timeout=180) as response, path.open("xb") as handle:
            while chunk := response.read(1024 * 1024):
                size += len(chunk)
                if size > MAX_OUTPUT_BYTES:

Tainted flow: 'request' from os.environ.get (line 1371, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/provider_adapters.py (reported line 1375)May include surrounding context.

python
request.add_header("Authorization", f"Bearer {token}")
        request.add_header("Content-Type", content_type)
        try:
            with urllib.request.urlopen(request, timeout=300) as response:
                raw = response.read(MAX_JSON_RESPONSE + 1)
                request_id = response.headers.get("x-request-id")
        except urllib.error.HTTPError as exc:

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description presents an operational skill whose purpose is to execute confirmed media production jobs in a short-drama project and persist outputs/results. The code chunk instead implements a self-test harness for that broader system. While it does validate an important described constraint—explicit confirmation gating—and touches provider payload assembly for image, video, and music, its primary behavior is testing, not production execution in response to creator commands. This is a material description-versus-behavior mismatch because the chunk’s main purpose is QA/verification infrastructure rather than the declared end-user production workflow.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
[production_tool.py](scripts/production_tool.py) 提供,然后运行:

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/provider_adapters.py (reported line 211)May include surrounding context.

python
outputs = job.get("outputs")
    if not isinstance(outputs, list) or len(outputs) != 1 or not isinstance(outputs[0], str):
        raise ValueError("provider adapter requires exactly one output")
    return prompt, dict(parameters)


def _prompt_with_reference_contract(

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/provider_adapters.py (reported line 226)May include surrounding context.

python
outputs = job.get("outputs")
    if not isinstance(outputs, list) or len(outputs) != 1 or not isinstance(outputs[0], str):
        raise ValueError("provider adapter requires exactly one output")
    return prompt, dict(parameters)


def _prompt_with_reference_contract(

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill declares substantial operational capabilities—filesystem access, shell execution, environment access, and possible network use—but does not scope or constrain them via an explicit permissions or allowed-tools declaration. In an agent setting, this increases the chance of unintended command execution, project file modification, credential exposure via environment reads, or overly broad tool access beyond what the production workflow strictly needs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example job sets prompt_language to zh-CN, and later requirements mandate a Chinese label field for bindings. This is a natural-language locale constraint presented as part of the contract rather than an explicit user-selectable option, which can violate language/locale policy for a general-purpose skill.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This adapter sends the text to be spoken verbatim to an external third-party API (api.minimax.io) for TTS generation. That creates a real data egress path: sensitive dialogue, personal information, or confidential project material could be transmitted off-platform, and the provider may retain, log, or process that content outside the user's direct control.

Content

Scanner excerpt · references/providers/minimax-speech.md (reported line 10)May include surrounding context.

text

Required environment: `MINIMAX_API_KEY`. `MINIMAX_BASE_URL` optionally overrides the default
`https://api.minimax.io/v1` and must remain HTTPS.

The job uses the suite's `tts` modality and must have exactly one output. The production prompt is the
line to be spoken, verbatim — not a description of it. Supported public parameters are `model`,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

L19 instructs that the voice choice must come from 视觉设定.md under the character's 声音方向, which hard-codes a Chinese-language documentation dependency. The file does not offer a language choice or explain why this locale-specific requirement is necessary, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/production_tool.py (reported line 1462)May include surrounding context.

python
def _run_adapter(command: list[str], timeout: int, payload: Mapping[str, Any], root: Path) -> dict[str, Any]:
    with tempfile.TemporaryFile() as stdout, tempfile.TemporaryFile() as stderr:
        try:
            completed = subprocess.run(
                command,
                input=_canonical(payload),
                stdout=stdout,

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module docstring states the CLI reads a job from stdin and writes only contract JSON to stdout after a provider result has been saved to a temporary regular file. However, the runtime also calls _record_handle to create or replace handle_path with a JSON file containing the provider job id before polling video tasks, introducing an additional on-disk side effect beyond the documented output flow.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module docstring asserts that the public compile_* functions are deterministic and perform no I/O. But compile_seedance_payload and compile_minimax_h3_payload are public compile functions in the same module, and the compile pipeline for provider payloads includes _inline_reference_urls, which reads project reference bytes from disk when preparing inputs for those providers; this contradicts the no-I/O claim at the module level about the compile surface.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/providers/gpt-image-2.md (reported line 10)May include surrounding context.

md
OPENAI_MODEL = "gpt-image-2"
MINIMAX_MUSIC_MODEL = "music-3.0"
OPENAI_BASE_URL = "https://api.openai.com/v1"
SEEDANCE_BASE_URL = "https://ark.cn-beijing.volces.com/api/v3"
MINIMAX_BASE_URL = "https://api.minimax.io/v1"
MINIMAX_VIDEO_BASE_URL = "https://api.minimax.io/v2"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/provider_adapters.py (reported line 32)May include surrounding context.

python
OPENAI_MODEL = "gpt-image-2"
MINIMAX_MUSIC_MODEL = "music-3.0"
OPENAI_BASE_URL = "https://api.openai.com/v1"
SEEDANCE_BASE_URL = "https://ark.cn-beijing.volces.com/api/v3"
MINIMAX_BASE_URL = "https://api.minimax.io/v1"
MINIMAX_VIDEO_BASE_URL = "https://api.minimax.io/v2"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/providers/minimax-h3-video.md (reported line 23)May include surrounding context.

md
MINIMAX_MUSIC_MODEL = "music-3.0"
OPENAI_BASE_URL = "https://api.openai.com/v1"
SEEDANCE_BASE_URL = "https://ark.cn-beijing.volces.com/api/v3"
MINIMAX_BASE_URL = "https://api.minimax.io/v1"
MINIMAX_VIDEO_BASE_URL = "https://api.minimax.io/v2"
MAX_JSON_RESPONSE = 128 * 1024 * 1024
MAX_OUTPUT_BYTES = 512 * 1024 * 1024

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/providers/minimax-music.md (reported line 10)May include surrounding context.

md
MINIMAX_MUSIC_MODEL = "music-3.0"
OPENAI_BASE_URL = "https://api.openai.com/v1"
SEEDANCE_BASE_URL = "https://ark.cn-beijing.volces.com/api/v3"
MINIMAX_BASE_URL = "https://api.minimax.io/v1"
MINIMAX_VIDEO_BASE_URL = "https://api.minimax.io/v2"
MAX_JSON_RESPONSE = 128 * 1024 * 1024
MAX_OUTPUT_BYTES = 512 * 1024 * 1024

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/provider_adapters.py (reported line 34)May include surrounding context.

python
MINIMAX_MUSIC_MODEL = "music-3.0"
OPENAI_BASE_URL = "https://api.openai.com/v1"
SEEDANCE_BASE_URL = "https://ark.cn-beijing.volces.com/api/v3"
MINIMAX_BASE_URL = "https://api.minimax.io/v1"
MINIMAX_VIDEO_BASE_URL = "https://api.minimax.io/v2"
MAX_JSON_RESPONSE = 128 * 1024 * 1024
MAX_OUTPUT_BYTES = 512 * 1024 * 1024

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/provider_adapters.py (reported line 35)May include surrounding context.

python
MINIMAX_MUSIC_MODEL = "music-3.0"
OPENAI_BASE_URL = "https://api.openai.com/v1"
SEEDANCE_BASE_URL = "https://ark.cn-beijing.volces.com/api/v3"
MINIMAX_BASE_URL = "https://api.minimax.io/v1"
MINIMAX_VIDEO_BASE_URL = "https://api.minimax.io/v2"
MAX_JSON_RESPONSE = 128 * 1024 * 1024
MAX_OUTPUT_BYTES = 512 * 1024 * 1024

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

_record_handle() writes to job['handle_path'] with no restriction that the path stay within a trusted project directory. If an attacker can influence the job input, they can cause arbitrary file creation or overwrite (subject to process permissions), which is broader than the stated skill purpose and can be abused to plant files in sensitive locations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language instruction in the default prompt is written entirely in English even though the skill metadata is otherwise in Chinese. This can impose a specific language on users or downstream agents without opt-in, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file documents use of ARK_API_KEY and an external API endpoint, but it does not include any warning that the skill sends requests to Volcengine using provided credentials. Under the markdown variant of SQP-2, descriptions should warn about behaviors affecting privacy or system integrity when external services and credentials are involved.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.