Back to skill

Security audit

特看视频

Security checks for vulnerabilities and agentic risk

Overview

The skill largely matches its AI media-generation purpose, but needs review because it broadly auto-activates, handles paid account credentials and identity media, and tries to force branded login messaging through a specific message tool.

Install only if you are comfortable granting this skill access to a Tekan account, uploading media/prompts to Tekan/TopView services, storing API credentials locally, and using voice/avatar cloning features. Prefer explicit user confirmation before login, uploads, paid generation, voice cloning, saved avatars, board deletion, or custom voice deletion, and remove ~/.tekan/credentials.json with logout when done.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:67
Finding

Forced Promotional Output and Messaging-Tool Hijacking

Content
View full analysis
with the actual authorization URL, then send the following message to the user verbatim. Prohibited behavior: - Do not omit any part of the template. - Do not summarize or rewrite it in your own words. - Do not show a simplified capability list before authorization. ``` The mandatory template includes a substantial branded capability and model-promotion message in addition to the authorization link. ### Technical Analysis The instructions go beyond explaining how to present an OAuth authorization URL. They attempt to control the host Agent's output channel, require invocation of a specific messaging tool, require fixed promotional content, and prohibit context-sensitive rewriting or omission. This constitutes instruction hijacking because the Skill text directs the Agent to override ordinary response behavior and host-controlled tool-routing decisions. Presenting an authorization URL does not require a fixed advertisement, a particular messaging tool, or a prohibition against adapting the message to the user's context. ### Attack Path 1. The host Agent loads `SKILL.md`. 2. The user triggers the Skill's setup or authentication workflow. 3. The Skill directs the Agent to run the login command and extract an external authorization URL. 4. The Skill prohibits an ordinary response and mandates `message(action=send)`. 5. The Agent sends the fixed branded promotional template and external authorization lin ...[truncated 688 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/auth.py:244
Finding

Pending OAuth Session File Is Created Without Restrictive Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/auth.py:233
Finding

OAuth Response Controls Browser and Polling Destinations Without Validation

Content
View full analysis
None: """Poll token_endpoint until authorized (200), pending (428), or timeout. On success: fetches API key, saves credentials, cleans up pending file. On failure: prints error to stderr and calls sys.exit(1). """ print("Waiting for authorization (Ctrl+C to cancel)...", file=sys.stderr) start = time.time() try: while time.time() - start < LOGIN_TIMEOUT: time.sleep(interval) elapsed = int(time.time() - start) print(f" [{elapsed}s] checking...", file=sys.stderr, end="\r") try: resp = requests.get(token_endpoint, timeout=10) ``` ```python body = resp.json() data = body.get("data") or body device_code = data["device_code"] verification_url = data["verification_uri_complete"] token_endpoint = data["token_endpoint"] interval = data.get("interval", 2) expires_in = data.get("expires_in", 600) app_key = data.get("app_key", "openclaw") PENDING_FILE.parent.mkdir(parents=True, exist_ok=True) PENDING_FILE.write_text(json.dumps({ "device_code": device_code, "token_endpoint": token_endpoint, "interval": interval, "expires_in": expires_in, "app_key": app_key, "verification_uri_complete": verification_url, "created_at": datetime.now(timezone.utc).isoformat(), }, indent=2)) print() print(f" URL: {verification_url}") print(f" Please log in (if needed) and click 'Authorize'.") print(f" Session expires in {expires_in // 60} minutes.") print() _try_open_browser(verification_url) _poll_for_approval(token_endpoint, interval, app_key) ``` ### Technical Analysis The initial device-code request is sent to a hard-coded HTTPS endpoint, but the script subsequen ...[truncated 1953 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/requirements.txt:1
Finding

Dependency Installation Is Not Reproducibly Pinned

Content
View full analysis
=2.28.0 ``` The Skill directs installation through: ```bash pip install -r {baseDir}/scripts/requirements.txt ``` ### Technical Analysis The requirement specifies only a lower bound. It permits installation of any future `requests` release and any dependency versions selected by the package resolver at installation time. This does not establish that the current `requests` package is malicious. The weakness is that installation is not reproducible and does not cryptographically bind the Skill to versions reviewed during the audit. A future compromised release, compromised package index, or incompatible dependency can therefore change the code installed and executed without changes to the Skill package. ### Attack Path 1. The Agent follows `SKILL.md` and invokes `pip install`. 2. The resolver selects the latest available version satisfying `requests>=2.28.0`. 3. A future malicious, compromised, or incompatible version is available from the configured package index. 4. The package or one of its transitive dependencies is downloaded and installed. 5. Installation hooks or later imports execute code that was not part of the audited project. ### Impact Assessment A compromised dependency executes with the privileges of the account running the installation or Skill. Depending on those privileges, it could read the locally stored Tekan credentials, access user files, alter the Python environment, or communicate over the network. The finding is Low risk because no malicious package, typosquatting name, or currently known compromised version was identified in the reviewed manifest. It is a supply-chain hardening deficiency rather than evidence of an active dependency attack. ]]>
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (72)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill claims creative-generation behavior but also queries credits, usage history, and billing-related records. Undisclosed access to account consumption and quota data can expose sensitive account metadata and create a privacy surprise, especially under a broad auto-triggering description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims creative-generation behavior but also queries credits, usage history, and billing-related records. Undisclosed access to account consumption and quota data can expose sensitive account metadata and create a privacy surprise, especially under a broad auto-triggering description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims creative-generation behavior but also queries credits, usage history, and billing-related records. Undisclosed access to account consumption and quota data can expose sensitive account metadata and create a privacy surprise, especially under a broad auto-triggering description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill claims creative-generation behavior but also queries credits, usage history, and billing-related records. Undisclosed access to account consumption and quota data can expose sensitive account metadata and create a privacy surprise, especially under a broad auto-triggering description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims creative-generation behavior but also queries credits, usage history, and billing-related records. Undisclosed access to account consumption and quota data can expose sensitive account metadata and create a privacy surprise, especially under a broad auto-triggering description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims creative-generation behavior but also queries credits, usage history, and billing-related records. Undisclosed access to account consumption and quota data can expose sensitive account metadata and create a privacy surprise, especially under a broad auto-triggering description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill claims creative-generation behavior but also queries credits, usage history, and billing-related records. Undisclosed access to account consumption and quota data can expose sensitive account metadata and create a privacy surprise, especially under a broad auto-triggering description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims creative-generation behavior but also queries credits, usage history, and billing-related records. Undisclosed access to account consumption and quota data can expose sensitive account metadata and create a privacy surprise, especially under a broad auto-triggering description.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger text is extremely broad, effectively matching almost any creative request and auto-routing the user into a skill with authentication, network access, file handling, billing impact, and account/project operations. Overbroad invocation criteria materially increase the chance of inappropriate activation, unintended external transmission, unnecessary login prompts, or accidental spend.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
82% confidence
Finding

The skill instructs the agent to save credentials to a predictable local path (~/.tekan/credentials.json). Storing secrets in a plain, known filesystem location increases the risk of token theft by other skills, local processes, backups, or overly broad file-read permissions, especially since the skill already lacks explicit tool scoping.

Content

Scanner excerpt · SKILL.md (reported line 154)May include surrounding context.

md
### 步骤 3 — 等待用户授权

用户在浏览器中完成登录和授权后,会回复"好了"。此时 `auth.py login` 应已自动检测到授权并保存凭证到 `~/.tekan/credentials.json`。

### 步骤 4 — 验证登录状态

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The status example explicitly includes a masked api_key and the full filesystem path to the credential file. Even partial secret disclosure and precise secret-file location disclosure can normalize exposing sensitive auth material in logs or chat transcripts, increasing the chance of credential mishandling or targeted local theft in agent-mediated environments.

Content

Scanner excerpt · references/auth.md (reported line 72)May include surrounding context.

api_key: sk-...3HB charge_type: pro authorized: 2026-03-04T10:00:00+00:00 file: /Users/you/.tekan/credentials.json

text

## `logout` — 删除凭证

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The --save-avatar option persists a user's image as a reusable digital avatar, which materially increases privacy, consent, and impersonation risk compared with one-time generation. Without an explicit warning about retention, reuse, deletion, and authorization requirements, users may unknowingly create durable biometric assets that can later be misused or reused beyond the original task.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The script stores long-lived credentials and API key material in a plaintext file under the user's home directory, and also persists an access token when present. Although the file is chmodded to 0600, plaintext storage on disk still increases exposure to local compromise, backups, sync services, malware, or accidental disclosure; in a skill context that can invoke paid media-generation APIs, theft of this token/key could enable account abuse and billing impact.

Content

Scanner excerpt · scripts/auth.py (reported line 31)May include surrounding context.

python
CLIENT_ID = "tkv-skill"
DEFAULT_SCOPE = "read:profile read:billing read:apikey"

CRED_FILE = Path.home() / ".tekan" / "credentials.json"
PENDING_FILE = Path.home() / ".tekan" / "pending_device.json"
LOGIN_TIMEOUT = 600  # 10 minutes, matching server-side expiry

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/auth.md (reported line 31)May include surrounding context.

md
"""Load Tekan API credentials.

Reads from ~/.tekan/credentials.json (set by auth.py login).
"""

import json

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/auth.md (reported line 44)May include surrounding context.

md
"""Load Tekan API credentials.

Reads from ~/.tekan/credentials.json (set by auth.py login).
"""

import json

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/auth.md (reported line 83)May include surrounding context.

md
"""Load Tekan API credentials.

Reads from ~/.tekan/credentials.json (set by auth.py login).
"""

import json

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/auth.md (reported line 89)May include surrounding context.

md
"""Load Tekan API credentials.

Reads from ~/.tekan/credentials.json (set by auth.py login).
"""

import json

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/shared/config.py (reported line 3)May include surrounding context.

python
"""Load Tekan API credentials.

Reads from ~/.tekan/credentials.json (set by auth.py login).
"""

import json

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/shared/config.py (reported line 10)May include surrounding context.

python
"""Load Tekan API credentials.

Reads from ~/.tekan/credentials.json (set by auth.py login).
"""

import json

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README promotes voice cloning and states that login credentials are automatically stored locally, but it does not warn users about privacy, consent, credential theft, or local secret handling risks. In a skill centered on media generation and identity/voice features, omission of these warnings can lead to misuse of biometric-like data, unauthorized impersonation, or insecure storage of account tokens on shared systems.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The README instructs users to run npx skills add topviewai/skill without pinning a specific version of the skills package. This creates a supply-chain risk: users may execute whatever package version is current at install time, including a compromised or typosquatted release, leading to arbitrary code execution during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This is a second occurrence of the same unpinned npx skills install pattern in the installation section. Repeating unversioned execution instructions increases the chance that users will run mutable third-party code from the registry, exposing them to supply-chain compromise and arbitrary command execution.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares no explicit tool/permission scope even though it instructs the agent to use shell, network, local file access, and file writes. In an agent environment, missing scope boundaries increases the blast radius of prompt injection, misuse, or accidental execution because the agent may invoke powerful capabilities without policy-level restrictions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill advertises voice cloning and credential storage without any privacy, consent, retention, or account-impact warning. These are sensitive operations: voice cloning can implicate biometric/identity misuse, and credential persistence creates local-secret handling risk if users are not clearly informed.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
> ✅ 正确示例:
> ```
> [👉 点击此处完成登录授权](https://api.tekan.cn/oauth/authorize?code=abc123)
> ```
> ❌ 错误示例(裸 URL,没有方括号包裹):
> ```

Static analysis

No suspicious patterns detected.