Back to skill

Security audit

volcengine-video

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its VolcEngine video-generation purpose, but it asks users to store API keys in a local skill file and can send prompts or task IDs to an external paid API under broad triggers.

Review before installing. Use a dedicated low-privilege VolcEngine key with quotas, avoid putting secrets in the skill directory, do not commit or share config.json, and avoid sending private, proprietary, or personal information in prompts unless you intend it to be processed by VolcEngine.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
config.json:1
Finding

Plaintext API credentials stored in the Skill directory

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README describes sending prompts and task IDs to VolcEngine but does not warn users that their input and related task data are transmitted to a third-party external API. This can lead to unintentional disclosure of sensitive prompts, internal project details, or identifiers, especially if users assume the skill operates locally or do not understand the data-sharing implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description does not warn users that their prompts and related task data will be transmitted to a third-party API. This creates a privacy and data-handling risk because users may include sensitive, proprietary, or personal information in prompts without realizing it leaves the local environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match many ordinary user requests about making or checking videos, which can cause the skill to activate unexpectedly. In this skill’s context, unintended activation is more dangerous because it may route user prompts and task identifiers to an external video-generation service without clear user intent or informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Documenting API credentials in a local config.json file without guidance on access controls, secret rotation, exclusion from version control, or safer secret storage encourages insecure secret management. If the file is exposed through source control, logs, backups, or permissive filesystem access, an attacker could steal the keys and abuse the external API account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code performs an outbound HTTP POST to visual.volcengineapi.com, transmitting the task identifier and signed request metadata. While the function purpose implies querying a remote service, the code lacks an explicit warning or disclosure that user-supplied task data will be sent over the network.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code accesses sensitive credentials by loading access_key and secret_key from config.json when they are not passed explicitly. Although the function docstring describes the parameters, there is no warning in code comments, prompts, or user-facing output that local credentials will be read automatically.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

With no manifest available, the only explicit intent comes from the code's video-generation docstring. The function goes beyond prompt-to-video transformation by sourcing secrets from environment variables, which is a privileged capability not justified by the stated functional description alone; the CLI path also reads secrets from config.json.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script sends the user-supplied prompt directly to an external VolcEngine API, but there is no explicit user-facing notice or consent step at the point of transmission. If prompts contain proprietary, personal, or otherwise sensitive data, this can cause unintended disclosure to a third party despite the HTTPS transport.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The file contains user-visible natural-language text in multiple languages, including a Chinese comment alongside otherwise English-facing strings. This can violate a language/locale policy when the skill does not explicitly offer or document language selection or localization behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.