Back to skill

Security audit

小云雀营销创作

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed XiaoYunque marketing-video API helper that uploads user-selected assets, submits generation jobs, checks status, and downloads results using a user-configured access key.

Install only if you intend to use XiaoYunque's marketing API and are comfortable setting XYQ_ACCESS_KEY locally. Treat uploads and generation as third-party processing that may consume account credits; review dry-run output before --execute and do not place secrets in chat, request files, command arguments, or logs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
node scripts/marketing.js upload --file /path/to/product.png

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
node scripts/marketing.js upload --file /path/to/product.png

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
node scripts/marketing.js upload --file /path/to/product.png

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
node scripts/marketing.js upload --file /path/to/product.png

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
node scripts/marketing.js upload --file /path/to/product.png

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill explicitly requires an environment variable (XYQ_ACCESS_KEY) and describes making real API requests for upload, query, and balance operations, but it does not declare an explicit tool scope such as permissions or allowed-tools. That creates a governance gap: the agent may be able to access secrets and perform outbound network actions without a narrowly declared boundary, increasing the risk of unintended secret use or external requests beyond what reviewers expect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language description is entirely in Chinese and specifies when the skill should be used, but does not offer any language choice or indicate that Chinese is optional. This can violate a language/locale policy when users have not opted into Chinese-language interaction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs the operator to upload the user's real local file to an external marketing API using configured credentials, but it provides no user-facing notice about third-party transmission, data handling, or credential-backed access. This creates a real privacy and consent issue because sensitive user media may be sent off-platform without clear disclosure or confirmation of what external service will receive it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instructions say to proceed from preview to execution and specifically state that no further authorization is needed once the user asked for generation, but they do not require a clear warning that the execute step submits a real external job that may consume credits or trigger irreversible processing. In context, this increases the risk of unintended spend and external processing without informed user confirmation at the point of action.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file embeds user-facing validation and help messages in Chinese throughout, including hard requirements and operational guidance, without any indication that the skill is China-specific or that users may choose another language. This is a natural-language locale policy issue because the skill effectively enforces a specific language by default.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.