Back to skill

Security audit

Pipaclaw Skills Hub

Security checks for vulnerabilities and agentic risk

Overview

The hub is mostly coherent, but one routed video skill provisions and stores cloud credentials and can send them to a configurable API origin without enough user-facing scoping or controls.

Review this skill before installing if you plan to use the promo-video workflow. It may create cloud project state, generate workspace links, and store a reusable API key on disk. Only use trusted environment settings for the Maliang/Nano base URL, and avoid running the helper scripts in shells or wrappers that can set untrusted `PROMO_VIDEO_MAKER_BASE_URL` or `MALIANG_HUB_BASE_URL` values.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
promo-video-maker/scripts/hub-api.sh:8
Finding

Bearer Credential Can Be Disclosed to an Untrusted Configurable API Origin

Content
View full analysis
Remediation
View remediation

other

Note
Location
promo-video-maker/scripts/bootstrap.sh:7
Finding

Automatic Provisioning Discloses the Local Machine Hostname

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (39)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description says this skill is a general front door/router for multiple public skills. The supplied code does not perform routing, user dispatch, or selection among presentation/social/promotional skills. Instead, it is a concrete bootstrap/provisioning script for one specific skill: promo video maker. It contacts an external backend, sends the machine hostname, receives an API key and short code, writes those secrets to disk, and prints service configuration details. Those are materially different behaviors and capabilities from the declared purpose, especially credential provisioning and local secret persistence, which are undeclared. Therefore this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared purpose describes a routing/front-door skill that directs users to other skills for various tasks. The supplied code instead implements a utility that reads a local file and converts its contents to base64. This is a materially different primary purpose and introduces file-access behavior that is not reflected in the description. While such encoding might be a supporting detail inside a promo-video workflow, this chunk by itself does not behave like a router/front door, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The declared description says this skill acts as a user-facing routing/front-door layer that sends users to the right skill for certain task categories. The supplied code does not implement routing logic or selection among presentation/social/video skills. Instead, it is a generic API client wrapper for a promo-video-maker component: it bootstraps, reads an API key from a config directory, and sends arbitrary authenticated HTTP requests to a configured base URL. Reading local secrets and invoking arbitrary backend paths are undeclared capabilities materially different from the declared front-door routing purpose. While this could be a supporting utility for some larger system, this code chunk itself does not match the stated primary behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description says this skill is a high-level routing/front-door capability that helps users get sent to the correct skill without exposing implementation details. The supplied code does not perform routing, skill selection, or user-facing orchestration. Instead, it implements a concrete backend utility for promotional media processing: repeatedly querying /api/v1/hub/tasks/{kind}/{task_id} to monitor an image or video task until completion, failure, or timeout. That is a materially different primary purpose from the declared front-door router, so this is a description/behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared purpose describes an orchestration/router skill that helps users reach the correct skill for presentations, social operations, or promo video production. The supplied code instead implements a narrow helper script that posts a request body to a quote endpoint. That is a materially different primary behavior from user routing/orchestration. While it may be a supporting component within a larger system, this code chunk itself exposes an undeclared capability—requesting quote data from an API—and does not reflect the described front-door routing behavior.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · promo-video-maker/scripts/bootstrap.sh (reported line 14)May include surrounding context.

sh
if [[ ! -f "$KEY_FILE" || ! -s "$KEY_FILE" ]]; then
  MACHINE_ID="$(hostname)"
  CURL_OPTS=(--http1.1 -sS)
  PROVISION_RESULT="$(curl "${CURL_OPTS[@]}" -X POST "$BASE_URL/api/v1/provision" \
    -H "Content-Type: application/json" \
    -d "{\"machine_id\":\"$MACHINE_ID\"}")"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The hub uses broad activation phrasing such as being the public 'front door' for users who do not know which skill to call, plus expansive example requests. In an agent environment, overly broad invocation criteria can cause this router to intercept many unrelated requests and steer users into downstream skills without adequate intent disambiguation, increasing the chance of unintended actions or data exposure across skill boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

All example user requests and the ambiguity-resolution question are written in Chinese, which implies a default language behavior for user-facing interaction. There is no statement that the user may choose another language or that the skill is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description is broad enough to capture many presentation-related requests without defining exclusion conditions or precedence rules. In a multi-skill environment, this can cause over-routing, unintended activation, and inappropriate handling of user tasks by this skill when a narrower or safer skill should have been selected.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language trigger examples are highly permissive and include vague user phrases like 'help me make a PPT' or 'I don't know how to start,' which can match ordinary brainstorming, summarization, or document-organization requests. That increases the chance of this skill activating too early and taking control before the user's actual need is disambiguated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file presents its guidance almost entirely in Chinese, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · ppt-maker/references/confirmation-policy.md (reported line 13)May include surrounding context.

md
Everything else should default to internal team judgment unless the user explicitly asked to review intermediate work.

## Do Not Ask the User to Decide

- card layout vs split layout
- palette tuning inside an already-fit style

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file contains natural-language guidance entirely in Chinese, beginning with a direct instruction at L003, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Line L03 states the architecture guidance in Chinese and uses directive language without any indication that language selection is optional. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · ppt-maker/SKILL.md (reported line 57)May include surrounding context.

md
- handing off either final outputs or a web project workspace

Do not split this into multiple public skills.
Do not ask the user to choose internal roles.

## Front-Door Rule

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · ppt-maker/references/team-gates.md (reported line 59)May include surrounding context.

md
- handing off either final outputs or a web project workspace

Do not split this into multiple public skills.
Do not ask the user to choose internal roles.

## Front-Door Rule

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · promo-video-maker/SKILL.md (reported line 18)May include surrounding context.

md
- handing off either final outputs or a web project workspace

Do not split this into multiple public skills.
Do not ask the user to choose internal roles.

## Front-Door Rule

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger list is broad and includes generic phrases like 'promo video', 'teaser', 'explainer', and '帮我做一个视频', which can cause the skill to capture requests that may belong to other workflows or require additional consent before routing into a production pipeline. In this skill, unintended invocation is more dangerous because downstream behavior includes quoting, project selection/creation, cloud persistence, workspace link generation, and helper-script/API execution, so misrouting can expose user data or start paid operations under the wrong context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The project-mode intake and rules require persisted cloud project state and workspace access, but the public skill text does not clearly warn users that their materials, outputs, and metadata may be stored remotely and made accessible through a web workspace. This creates a consent and privacy gap, especially for creative briefs or source materials that may contain sensitive business or personal content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill states that helper scripts and Hub execution reuse the same cloud account and API key flow, but it does not clearly disclose this operational boundary or associated risks to users. If the skill is invoked unexpectedly or with untrusted inputs, this shared credential model can lead to unintended API actions, billing exposure, or broader account impact because transport scripts execute under the product's cloud identity.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · promo-video-maker/references/director-mode.md (reported line 20)May include surrounding context.

md
## What it should not do

- hide all intermediate stages in a black box
- create duplicate projects without checking
- pretend rough generated assets are a finished episode

## Suggested phase targets

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The routing rule hard-codes a clarification question in Chinese without checking the user's language or offering localization. This can confuse users, degrade informed consent around workflow selection, and create a poor or exclusionary experience, especially when the surrounding interaction is otherwise in another language.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script persists an API key and short code under a user config directory without clearly justifying why a routing hub needs durable service credentials. Persistent local secrets increase exposure to local compromise, accidental reuse, and confusion about what authority the hub now has on behalf of the user.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The bootstrap script goes beyond a routing-only hub role by contacting a remote provisioning service, obtaining credentials, and persisting them locally. That creates an undisclosed trust boundary and expands the blast radius: running the skill causes account/bootstrap state to be created on an external service and leaves usable credentials on disk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.