Back to skill

Security audit

视频解说脚本

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for Chinese video narration work, but its review step can send unpublished narration and transcript evidence to an external MiMo API without clear user-facing disclosure.

Install only if you are comfortable with a Chinese-language video scripting workflow that may send narration, transcript/ASR, visual-evidence summaries, plans, and optional research to the configured MiMo API during review. Use it on a narrow work_dir, avoid confidential or unreleased production material unless third-party API review is approved, and inspect generated project changes before applying them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (33)

Tainted flow: 'req' from os.environ.get (line 197, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/lib.py (reported line 198)May include surrounding context.

python
for attempt in range(max_retries):
        try:
            req = urllib.request.Request(endpoint, data=data, headers=headers)
            with urllib.request.urlopen(req, timeout=300) as resp:
                return json.loads(resp.read().decode("utf-8"))
        except urllib.error.HTTPError as e:
            body = _sanitize_api_error(e.read().decode("utf-8", errors="replace"))

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

该代码与声明存在明显的范围不一致。声明把技能定位为一个完整的视频策划与解说生成/校验、以及宣发文案处理工具;而实际代码片段只是一个 lint/预算辅助模块,核心用途是根据时间窗、语速配置和 TTS 额外静音开销计算可容纳的解说字数,并提供场景匹配函数。虽然“解说并校验”中的“校验”与该模块有一定关联,因此它可能是整体技能的一个支持性组成部分,但就所给代码片段本身而言,既没有实现导演与剪辑策划,也没有生成带时间戳解说、宣发标题、花字修订或文案回填等主要声明能力。因此应判定为描述与该代码片段实际行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个内容策划与文案生成/回填型技能,核心应是基于分析结果产出导演策划、剪辑方案和解说文案,并对成片宣发文案进行处理。但代码文件 deslop_qc.py 明确自述为“report-only”,且“never rewrites text”。其实际行为是:读取 narration 列表,并可附加读取 work_dir 下的 original_subtitles.json 与 style_card.json;对文本执行正则和词频规则检查,识别破折号、占位符泄漏、模板化转折、套话密度、抽象词密度、推理链、比喻标记、连接词不足、过长段落等问题;最后返回结构化 QC 报告。也就是说,这段代码只是解说文本的质检子模块,而不是所声明的完整技能主体。虽然声明里提到“校验”,与此代码有少量相关性,但仅凭该代码无法支撑声明中的主要功能,因此属于明显的描述与行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个高层内容生产技能,输入应包括分析结果与工程/内容证据,输出应包括 story plan、visual/audio board、style card、clip plan、narration 等多个文件,并支持宣发与文案返修场景。实际提供的代码块却只是一个小型工具模块,处理 narration block 的时间锚点建议、相邻块安全间隔、窗口约束和 handoff 判定,没有任何读取 work_dir、生成策划文件、撰写中文解说、宣发文案处理或回填逻辑。虽然该代码可能作为“解说校验”中的一个支持性子功能存在,但就该代码块本身而言,其行为范围与声明的主要用途差距很大,属于明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个上层创作/策划型技能,核心能力应是基于视频分析产出导演思路、剪辑策划、带时间戳中文解说词,以及宣发文案返修与回填。当前代码块却是底层的数据处理与证据整理模块:coverage_policy_v1 负责选取开头/中段/结尾及旁白窗口等覆盖区间;filter_evidence_by_ranges 仅筛选落在这些区间内的 visual/asr 条目;build_evidence_bundle 组装 evidence bundle;render_evidence_bundle 将其格式化为文本。虽然它涉及 narration、vlm_analysis、asr 和 research,这些输入与声明场景相关,但用途只是“审阅证据选择与展示”,并非声明中的主要交付物生成。因而该代码的主要行为与声明的主要目的明显不一致,属于能力与用途层面的实质性不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个高层内容生产与校验技能,核心能力应包括视频策划、解说写作、产物生成,以及部分文案返修流程。给出的代码片段则是一个非常窄的辅助脚本:根据已有 lint report 生成控制台可读摘要,针对 narration.json/original_subtitles.json 的问题给出标签、细节和修改提示。这可以算“校验流程”的配套展示层细节,但从该片段本身看,主要目的与声明的主要功能明显不一致,且缺失声明中几乎全部核心能力,因此应判定为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个面向内容策划与文案生产的技能,核心能力应是生成导演思路、剪辑方案、解说词及宣发文案,并产出多个策划/文案文件。实际代码却没有任何文案生成、策划编排、标题修订或 narration 校验逻辑;它只是一个底层辅助脚本,用于读取 vlm_analysis/asr/clip plan 等工件,并把源素材证据映射到 cut output 时间线上,明显服务于后续 review/grounding 环节。虽然声明中提到“校验”,但该代码仍不是在校验解说内容本身,而是在准备审查证据数据,因此其主要目的与声明的主要用途存在实质偏差。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个高层创意策划/文案生产技能:根据分析结果生成导演与剪辑方案、撰写并校验解说词,或处理宣发文案返修。而代码块仅实现一个底层语音证据分析模块,负责从 asr_clean.json、asr_result.json、silence_periods.json、speech_boundary_anchors*.json、clip_plan_validated.json 等文件中提取证据,判断旁白时间段是否覆盖源语音/对白,并返回 overlaps_speech 标记。这可以被某些“解说校验”流程间接使用,但它既不生成策划内容,也不处理宣发文案,且其主要输入/输出与声明明显不同,因此属于实质性描述不符。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

声明描述的是一个覆盖“策划 + 写解说 + 校验 + 宣发文案处理”的综合技能,且强调会产出多类策划文件。实际提供的代码块却只是 validate.py,一个单一用途的校验脚本:检查 narration.json 是否存在,调用 validate_narration_or_raise 做 lint,针对 cut_output 做 output timeline 边界检查,并调用 measure_narration_speech_ownership 回写测量结果。它没有生成导演策划、剪辑方案、宣传文案,也没有处理花字修订或文案回填。虽然“校验解说词”属于声明中的一部分,但代码行为明显只覆盖其中很小的一环,且主功能与声明的整体能力范围不一致,因此应判定为描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The RUBRIC string requires the reviewing behavior to operate in Chinese and specifies Chinese-only output conventions, but the file does not offer a language choice or indicate that this is an explicitly region-specific skill. This is a natural-language locale policy issue because it imposes a specific language without opt-in.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill declares extensive operational behavior, including reading and writing files, invoking local scripts, and potentially using network-capable execution, but it does not define any explicit tool scope or permission boundary. This creates ambient-authority risk: if the runtime grants broad defaults, the skill may access more files, environment data, or external resources than intended.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description explicitly says the skill writes timestamped Chinese narration (“写带时间戳的中文解说”), which imposes a language constraint in natural language. The file does not indicate that the user can choose another language or that Chinese is optional or justified as a region-specific requirement.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list contains broad, everyday phrases such as generic writing and narration requests, which can cause the skill to activate in contexts the user did not intend. Unintended activation can route unrelated user content into this skill's file-handling and script-driven workflow, increasing the chance of incorrect processing or exposure of local project data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire skill reference is written as mandatory Chinese-language operating guidance for the agent, with no indication that the user may choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill is written as a Chinese-only workflow and gives no indication that users may choose another language or locale. Under the policy for natural-language constraints, forcing a specific language without opt-in is a reportable issue unless the regional limitation is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The docstring on L09 is written in Chinese while the rest of the file is English, indicating a language-specific instruction or documentation choice without any visible user opt-in or documented locale constraint. This matches the policy concern for forcing a specific language/locale absent justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This Python file contains multiple hard-coded Chinese strings in generated evidence text and rendered output, including labels like '帧实', '画面', '对白', and '(无 timeline evidence)'. Because the file does not offer a language/locale option or document that it is intentionally limited to a Chinese-speaking context, it violates the policy against forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib.py (reported line 16)May include surrounding context.

python
# ── 配置 ──────────────────────────────────────────────────────────────

DEFAULT_MIMO_API_URL = "https://api.xiaomimimo.com/v1"
DEFAULT_MIMO_TOKEN_PLAN_CLUSTER = "cn"
MIMO_TOKEN_PLAN_API_URLS = {
    "cn": "https://token-plan-cn.xiaomimimo.com/v1",

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code contains multiple user-facing log and error messages written only in Chinese, such as the docstring and runtime messages in api_call. For an all-file-types policy check, this is a locale/language constraint without any visible opt-in, fallback, or justification that the skill is intended only for Chinese-speaking users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file emits user-facing console summaries and remediation hints entirely in Chinese, including labels, status lines, and guidance strings. Because this behavior is hard-coded throughout the skill and there is no visible opt-in, fallback, or locale selection mechanism, it constitutes a language/locale policy violation under the stated rules.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This file includes user-facing natural-language strings in Chinese, such as the over-budget error message, without indicating that the skill is Chinese-only or giving the user a language/locale option. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The success message narration lint:通过 is emitted directly to users/log consumers in Chinese only. There is no indication in this file that users can opt into this locale or that the tool is explicitly region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
77% confidence
Finding

When JSON parsing fails, the function returns the first 2000 characters of the raw model response in a raw field. That content is later available to downstream consumers, but this file provides no warning, logging disclosure, or comment alerting users that malformed responses may be retained and surfaced verbatim.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code sends narration text plus grounding data derived from VLM/ASR inputs to an external model API via api_call(...) without any disclosure, consent check, or local-only alternative visible in this file. In this skill context, the transmitted content may include unpublished video material, transcripts, or other sensitive production data, so silent exfiltration to a third-party service creates a real confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The docstring says validation 'never rewrites the agent's text, timing, order or metadata,' yet also says full and cut_output 'persist' measured overlaps_speech ownership. The code implements that persistence by recalculating narration via measure_narration_speech_ownership and writing the modified structure back to narration.json, so the documentation contradicts the actual side effect on metadata.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.