扫描报告
20 /100
tiktok-viral-editor-zh
TikTok爆款视频剪辑skill,使用Sparki AI进行视频编辑
Legitimate TikTok video editing skill with clean implementation, no malicious patterns, and proper credential handling.
可以安装
This skill is safe to use. The only minor issue is that download_result() fetches from variable URLs (not just sparki.io), but this is necessary for video delivery and is standard practice for cloud-based video services.
安全发现 2 项
| 严重性 | 安全发现 | 位置 |
|---|---|---|
| 低危 | Download URLs not explicitly declared in network permissions 文档欺骗 | src/sparki_cli/client.py:95 |
| 低危 | Dependencies not version-pinned 供应链 | pyproject.toml:10 |
| 资源类型 | 声明权限 | 推断权限 | 状态 | 证据 |
|---|---|---|---|---|
| 文件系统 | READ | READ | ✓ 一致 | cli.py:79-81 reads sparki_history.json |
| 文件系统 | WRITE | WRITE | ✓ 一致 | config.py:36 saves to ~/.openclaw/config/sparki.json |
| 网络访问 | agent-api.sparki.io | agent-api.sparki.io + variable CDN URLs for downloads | ✓ 一致 | client.py:95 downloads from result_url parameter |
| 环境变量 | SPARKI_API_KEY | SPARKI_API_KEY, SPARKI_UPLOAD_TG_LINK | ✓ 一致 | config.py:18-21 reads from os.environ |
7 项发现
中危 外部 URL 外部 URL
https://img.shields.io/badge/ClawHub-Skill-blueviolet README.md:3 中危 外部 URL 外部 URL
https://clawhub.io README.md:3 中危 外部 URL 外部 URL
https://img.shields.io/badge/version-1.0.12-blue README.md:4 中危 外部 URL 外部 URL
https://sparki.io SKILL.md:17 中危 外部 URL 外部 URL
https://agent-api.sparki.io src/sparki_cli/constants.py:61 中危 外部 URL 外部 URL
https://t.me/Sparki_AI_bot/upload src/sparki_cli/constants.py:62 中危 外部 URL 外部 URL
https://sparki.io/pricing src/sparki_cli/constants.py:101 目录结构
11 文件 · 33.3 KB · 1009 行 Python 7f · 904L
Markdown 2f · 70L
TOML 1f · 31L
JSON 1f · 4L
├─
▾
src
│ └─
▾
sparki_cli
│ ├─
__init__.py
Python
│ ├─
cli.py
Python
│ ├─
client.py
Python
│ ├─
config.py
Python
│ ├─
constants.py
Python
│ ├─
models.py
Python
│ └─
output.py
Python
├─
_meta.json
JSON
├─
pyproject.toml
TOML
├─
README.md
Markdown
└─
SKILL.md
Markdown
依赖分析 3 项
| 包名 | 版本 | 来源 | 已知漏洞 | 备注 |
|---|---|---|---|---|
typer | >=0.9.0 | pip | 否 | Version not pinned |
httpx | >=0.27.0 | pip | 否 | Version not pinned |
pydantic | >=2.0.0 | pip | 否 | Version not pinned |
安全亮点
✓ No shell execution, subprocess, or system command invocations detected
✓ No base64 encoding or obfuscated code patterns
✓ No credential exfiltration - API key is stored locally only
✓ No sensitive file access (no ~/.ssh, ~/.aws, .env file reading)
✓ No network C2 communication or data exfiltration patterns
✓ Clean Python codebase with no reverse shell or backdoor code
✓ API key properly scoped to authenticated API calls only
✓ All file operations confined to declared config directories