Back to skill

Security audit

FMT视频制作工具 v1.0

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent FMT video-production helper, but it instructs automatic external delivery and possible system package installation without clear user approval or destination controls.

Review before installing. Use it only in an environment where sending generated medical-education media to the configured TTS service, CDN, and Feishu destination is acceptable, and require manual confirmation before any upload or send action. Do not allow the skill to install system packages unless an administrator has approved the exact package source and command.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

other

Warning
Location
SKILL.md:83
Finding

Automatic External Transmission of Generated Media Without Explicit User Authorization

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:315
Finding

Unapproved System Package Installation in the FFmpeg Fallback Workflow

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 8)May include surrounding context.

md
---
AIGC:
    ContentProducer: Minimax Agent AI
    ContentPropagator: Minimax Agent AI
    Label: AIGC
    ProduceID: "00000000000000000000000000000000"
    PropagateID: "00000000000000000000000000000000"
    ReservedCode1: 3046022100eebc155dae2d5c8f31401b642391494516d5208bf8e92735508c06634d9e28e3022100be14e766a0954c64fb0118ca6a5f8ca12f0b92ca82b2fe91921ba67bb07d1a6e
    ReservedCode2: 3046022100a06382f12975c56bcbbec487df626f5a3317e7af7489d0b1288152357461dfe1
description: FMT肠菌移植科普视频制作工具(视频合成+字幕+SRT+配音TTS+片头片尾)。将静态图片/动态视频素材合成为完整科普视频,支持中文字幕、旁白配音、片头片尾合成。触发词:合成视频/添加字幕/视频配音/制作FMT视频。
name: fmt-video-production
version: 1.0.0
---

# FMT视频制�

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The description and tool instructions consistently specify Chinese subtitles, Chinese narration, and Chinese title text, but do not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-only regional context. This can violate a language/locale policy when a fixed language is imposed without opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow states that outputs are uploaded to a CDN and sent via Feishu, but this external data transfer is not disclosed in the skill description or user-facing consent flow. In a medical-content workflow, generated videos, narration text, and metadata may contain sensitive institutional or patient-adjacent information, so undisclosed exfiltration to third-party services creates privacy, compliance, and data-governance risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly instructs the agent to run apt-get install ffmpeg as a fallback. Allowing package installation expands the execution surface beyond the declared video-processing workflow, can modify the runtime environment, and may enable unreviewed code introduction or privilege-sensitive operations if the agent has sufficient permissions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.