Back to skill

Security audit

萤火虫多媒体设计助手

Security checks for vulnerabilities and agentic risk

Overview

This Firefly-branded media skill is mostly coherent, but it needs review because it can alter the Python environment, send text to an online TTS service, load third-party code in generated pages, and generate unsafe HTML from untrusted product data.

Install only if you want a Firefly Air Compressor branded creative workflow and are comfortable with local file processing, optional package installation, and online TTS. Use trusted input files only, avoid sensitive text with the TTS feature unless you accept remote processing, and review generated HTML before publishing because untrusted YAML or OCR-derived content could inject active page content.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (7)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:169
Finding

Mandatory Third-Party Branding and Promotional Content in Generated Outputs

Content
View full analysis
📞 {{CTA_PHONE}} ({{CTA_PERSON}}) 📧 aifirefly@163.com
萤火虫空压机
萤火虫空压机
专注空压机节能 · 为企业省气省电
📞 {{CTA_PHONE}}
``` ```html

获取报价与技术咨询

专业团队为您提供一对一节能解决方案

``` ### Technical Analysis The Skill instructions require generated content to use a specific company's visual identity, while the default page template inserts that company's name, email address, telephone CTA, and website link. These additions are not necessary for the underlying product-page generation task. Because these directives are part of the Skill's controlling instructions and default templates, generated outputs are systematically altered to include third-party promotional material unless users manually remove it. ### Attack Path 1. A user requests a product detail page. 2. The agent loads the Skill and follows its mandatory branding rules. 3. T ...[truncated 610 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_detail_page.py:85
Finding

Stored HTML and Script Injection Through Unescaped YAML Product Data

Content
View full analysis
rows for the specs table.""" rows = [] for spec in specs: label = spec.get("label", "") value = spec.get("value", "") rows.append(f'{label}{value}') return "\n ".join(rows) def build_features_html(features): """Generate feature cards HTML.""" cards = [] for feat in features: icon_key = feat.get("icon", "zap") emoji = ICON_EMOJI.get(icon_key, "⭐") title = feat.get("title", "") title_en = feat.get("title_en", "") desc = feat.get("desc", "") desc_en = feat.get("desc_en", "") title_display = title desc_display = desc if title_en: title_display += f" / {title_en}" if desc_en: desc_display += f"
{desc_en}" card = f"""
{emoji}
{title_display}
{desc_display}
""" cards.append(card) return "\n".join(cards) ``` ```python def build_gallery_html(images): """Generate thumbnail gallery HTML.""" if not images: return "" thumbs = images.get("thumbnails", []) if not thumbs: return "" items = [] for img in thumbs: items.append(f'Product view') return f"""
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/video_edit.py:108
Finding

FFmpeg Concat Manifest Injection Through Crafted Filenames

Content
View full analysis
{output} ...", end=" ", flush=True) success = run_ffmpeg(cmd, msg) os.unlink(list_path) ``` ### Technical Analysis The script creates an FFmpeg concat-demuxer manifest by interpolating absolute filenames between single quotes. It does not escape embedded apostrophes, backslashes, carriage returns, or newline characters. The `-safe 0` option further permits otherwise unsafe paths. Although `subprocess.run` uses an argument list and therefore avoids shell injection, the vulnerable parser is FFmpeg's concat demuxer. A crafted local filename can alter the structure of the generated manifest and introduce extra file entries or directives. The temporary file is also removed only after `run_ffmpeg` returns normally. Unexpected exceptions before `os.unlink` can leave it behind. ### Attack Path 1. An attacker creates a valid media file whose filename contains an apostrophe or newline followed by concat-manifest syntax. 2. The filename passes `os.path.isfile`. 3. The user or automated workflow includes that file in th ...[truncated 683 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ocr_image.py:143
Finding

Spreadsheet Formula Injection in OCR CSV Export

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/install_deps.py:22
Finding

Unpinned Third-Party Package Installation From the Ambient Pip Index

Content
View full analysis
Remediation
View remediation

other

Warning
Location
scripts/text_to_speech.py:96
Finding

Undisclosed Transmission of User Text to Microsoft Edge TTS

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
assets/3d-template.html:72
Finding

Generated 3D Pages Execute CDN-Hosted JavaScript Without Integrity Protection

Content
View full analysis
{"imports":{"three":"https://unpkg.com/three@0.160.0/build/three.module.js","three/addons/":"https://unpkg.com/three@0.160.0/examples/jsm/"}}
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (34)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a broad multimedia toolkit with image processing, OCR, video editing, TTS, 3D display building, and detail page creation. However, the supplied code only implements one narrow function: generating a product detail page HTML from YAML plus a template. It does not perform any image manipulation, OCR, video processing, or voice synthesis. It does include optional insertion of a 3D viewer iframe section and bilingual content fields, which partially aligns with the description, but the overall declared purpose materially overstates what this code chunk actually does. Therefore this chunk does not accurately represent the full declared functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code does partially match the declared description's video-editing subset: it supports trimming, concatenation, audio overlay/replacement, and resizing. However, the declared purpose presents a broad all-in-one creative toolkit spanning image processing, OCR, TTS, 3D display creation, and product page generation, none of which appear in this code chunk. Additionally, the code performs two concrete capabilities not mentioned in the description for this component: video metadata inspection and screenshot extraction. Because the actual code's scope is a narrower FFmpeg-based video CLI utility rather than the broadly declared multimedia toolkit, and it includes undeclared video-specific functions, this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
python scripts/video_edit.py trim input.mp4 --start 0:30 --end 2:45 -o trimmed.mp4

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
python scripts/video_edit.py trim input.mp4 --start 0:30 --end 2:45 -o trimmed.mp4

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

md
python scripts/video_edit.py trim input.mp4 --start 0:30 --end 2:45 -o trimmed.mp4

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 117)May include surrounding context.

md
python scripts/video_edit.py trim input.mp4 --start 0:30 --end 2:45 -o trimmed.mp4

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The phrase '直接用中文告诉 Claude 你的需求就行' instructs users to use Chinese as the interaction language, but does not indicate that other languages are also acceptable. This can be a language/locale policy issue because it imposes a specific language without explicit user opt-in or alternative choice.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares executable capabilities that imply file reads, file writes, and shell access, but it does not define any explicit tool scope or allowed-tools restrictions. In a user-invocable skill that processes arbitrary media and templates, this increases the blast radius of prompt-induced or accidental filesystem/shell actions because there is no policy boundary limiting what the skill may touch.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Broad trigger phrases like generic creative-editing terms can cause the skill to activate for ordinary user requests that did not intend to grant a media-processing workflow shell/file access. Unintended invocation is dangerous here because the skill is user-invocable, supports code/script execution paths, and may read/write files or call external tools based on loosely matched requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Per-feature triggers such as OCR, crop, resize, TTS, or product page are common cross-domain terms and may incorrectly route unrelated requests into this skill. Because the skill advertises multiple execution modes and external tooling, ambiguous routing can expose users to unintended file processing, shell commands, or data transformation beyond what they expected.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The HTML document declares lang="zh-CN", and the visible interface text throughout the template is Chinese-only. This imposes a specific language/locale on users without any opt-in, fallback, or explanation that the skill is intended only for a Chinese-speaking or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file includes natural-language output rules that require specific localized conventions, such as using the Chinese unit "万元" for all monetary amounts. The policy provided says to flag language or locale constraints when a skill forces a specific language/locale without user opt-in, and this section does not offer any choice or explain that the skill is region-specific.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script probes system commands and can install Python packages, which are host-modifying behaviors outside the core creative-editing functionality described in the skill manifest. In an agent skill context, this is more dangerous because users may invoke creative features without expecting the skill to alter the runtime environment or pull code from external registries.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/install_deps.py (reported line 129)May include surrounding context.

python
tool_name, url = tool_info
    shell = sys.platform == "win32"
    try:
        r = subprocess.run(
            [cmd, "--version"], capture_output=True, text=True,
            timeout=10, shell=shell
        )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/install_deps.py (reported line 139)May include surrounding context.

python
except Exception:
        pass
    try:
        r = subprocess.run(
            [cmd], capture_output=True, text=True,
            timeout=10, shell=shell
        )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
92% confidence
Finding

This code performs automatic package installation via pip, which executes network-fetching and package installation actions on the host. Even though package names are hardcoded, installing dependencies at runtime expands the trust boundary to PyPI and the local Python environment, creating supply-chain and environment-modification risk that goes beyond a simple dependency check.

Content

Scanner excerpt · scripts/install_deps.py (reported line 157)May include surrounding context.

python
for pkg_name, install_cmd in packages:
        print(f"    {pkg_name}...", end=" ")
        try:
            subprocess.check_call(
                [sys.executable, "-m", "pip", "install", pkg_name],
                stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL,
                timeout=300,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script defaults --lang to zh, which means user-facing status and error messages are shown in Chinese unless the caller explicitly overrides it. This imposes a specific language by default rather than offering a neutral prompt or requiring user selection, which is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
88% confidence
Finding

On Windows, this check uses subprocess.run with shell=True while invoking a command name that may be resolved through the shell or PATH. If an attacker can influence the execution environment or PATH, they may cause an unintended executable or script to run during the availability check.

Content

Scanner excerpt · scripts/text_to_speech.py (reported line 73)May include surrounding context.

python
def check_edge_tts_cli():
    """Check if edge-tts CLI is available."""
    try:
        r = subprocess.run(
            ["edge-tts", "--version"], capture_output=True, text=True, timeout=10,
            shell=(sys.platform == "win32")
        )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
79% confidence
Finding

This subprocess call also enables shell=True on Windows unnecessarily. Although the arguments are not directly user-controlled, shell invocation increases exposure to environment-based command resolution and unexpected shell behavior, which is avoidable in a helper check.

Content

Scanner excerpt · scripts/text_to_speech.py (reported line 83)May include surrounding context.

python
pass
    # Try python -m edge_tts
    try:
        r = subprocess.run(
            [sys.executable, "-m", "edge_tts", "--help"], capture_output=True, text=True, timeout=10,
            shell=(sys.platform == "win32")
        )

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script sends supplied text to the Edge TTS service, which means potentially sensitive user content leaves the local environment. In a creative-content skill this is expected functionality, but without an explicit notice or consent flow it can still create a privacy and data-handling risk.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/text_to_speech.py (reported line 106)May include surrounding context.

python
"--write-media", output_path,
    ]

    subprocess.run(cmd, check=True, capture_output=True, text=True, timeout=120)


def main():

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/video_edit.py (reported line 65)May include surrounding context.

python
def run_ffmpeg(cmd, msg):
    """Run an FFmpeg command and handle errors."""
    try:
        result = subprocess.run(cmd, capture_output=True, text=True, timeout=600)
        if result.returncode != 0:
            stderr = result.stderr.split("\n")[-5:] if result.stderr else ["Unknown error"]
            print(f"[✗] {msg['error']}:")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/video_edit.py (reported line 222)May include surrounding context.

python
]

    try:
        result = subprocess.run(cmd, capture_output=True, text=True, timeout=30)
        if result.returncode != 0:
            print(f"[✗] {msg['missing_ffprobe']}")
            return 1

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
86% confidence
Finding

This subprocess call enables shell=True on Windows even though it is only checking tool availability. Using shell invocation increases attack surface because command resolution depends on the shell environment and can be influenced by PATH or shell behavior, which is unnecessary here and riskier in an agent context that may process untrusted environments or run on shared hosts.

Content

Scanner excerpt · scripts/video_edit.py (reported line 281)May include surrounding context.

python
"""Check if ffmpeg and ffprobe are available."""
    for tool in ["ffmpeg", "ffprobe"]:
        try:
            r = subprocess.run(
                [tool, "-version"], capture_output=True, text=True, timeout=10,
                shell=(sys.platform == "win32")
            )

Static analysis

No suspicious patterns detected.