Back to skill

Security audit

SRT to Video

Security checks for vulnerabilities and agentic risk

Overview

The skill does the advertised SRT-to-video work, but its template installs a Remotion version with confirmed critical security advisories.

Install only after updating remotion, @remotion/cli, and related Remotion packages to 4.0.410 or newer, regenerating the lockfile, and running npm audit. Treat SRT files from untrusted sources cautiously and render in a contained project directory.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (11)

Known Vulnerable Dependency: remotion==4.0.242 — 2 advisory(ies): CVE-2026-30120 (Remotion: remote code execution (RCE) vulnerability); CVE-2026-30121 (Remotion: arbitrary file write vulnerability)

Critical
Category
Supply Chain
Confidence
98% confidence
Finding

The manifest explicitly pins remotion to 4.0.242, and the finding reports known critical advisories including remote code execution and arbitrary file write. In the context of a skill that converts SRT input into videos and may process attacker-controlled subtitle content during rendering, a vulnerable media/rendering dependency materially increases the risk of host compromise or filesystem tampering.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill content is written entirely in Chinese, including headings, workflow, rules, and examples, while the manifest description does not state that the skill is intentionally China-specific or limited to Chinese-speaking users. This creates a language/locale constraint without user opt-in, which matches the policy-violation criterion for forced language selection.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · templates/package.json (reported line 13)May include surrounding context.

json
"dependencies": {
    "@remotion/cli": "4.0.242",
    "@remotion/google-fonts": "4.0.242",
    "react": "^18.3.1",
    "react-dom": "^18.3.1",
    "remotion": "4.0.242"
  },

Unverifiable Dependency: react has 2 known advisory(ies) (CVE-2013-7035 (Cross-Site Scripting in react); GHSA-hg79-j56m-fxgv (Cross-Site Scripting in react)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · templates/package.json (reported line 14)May include surrounding context.

json
"@remotion/cli": "4.0.242",
    "@remotion/google-fonts": "4.0.242",
    "react": "^18.3.1",
    "react-dom": "^18.3.1",
    "remotion": "4.0.242"
  },
  "devDependencies": {

Unverifiable Dependency: react-dom has 1 known advisory(ies) (CVE-2018-6341 (Cross-Site Scripting in react-dom)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · templates/package.json (reported line 18)May include surrounding context.

json
"remotion": "4.0.242"
  },
  "devDependencies": {
    "@types/react": "^18.3.11",
    "typescript": "^5.6.3"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · templates/package.json (reported line 19)May include surrounding context.

json
},
  "devDependencies": {
    "@types/react": "^18.3.11",
    "typescript": "^5.6.3"
  }
}

Static analysis

No suspicious patterns detected.