Back to skill

Security audit

auto-remotion

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Remotion video-editing workflow, but it needs Review because it normalizes mutable package and third-party skill installs plus cloud transcription/TTS without enough privacy and provenance controls.

Install only if you are comfortable reviewing and approving the setup commands yourself. Prefer pinned package versions, avoid --force unless necessary, inspect any third-party skills before installing them globally, and do not send recordings or transcripts to cloud transcription/TTS services unless the material is approved for that handling.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:123
Finding

Unpinned Packages and Mutable Third-Party Skill Installations

Content
View full analysis

Vulnerability Details

File Locations:

  • README.md:24-28
  • README.md:34-37
  • SKILL.md:54-59
  • SKILL.md:75-81
  • SKILL.md:123-161
  • SKILL.md:339-341

Vulnerability Type: Supply-chain exposure through unpinned packages and mutable third-party Skills
Risk Level: Medium

Vulnerable Code

README.md:24-28:

bash
openclaw skills install 16miku/auto-remotion

npx clawhub@latest install 16miku/auto-remotion

README.md:34-37:

bash
npx create-video --yes --blank --no-tailwind my-video
cd my-video
npm install
npm run dev

SKILL.md:54-59:

bash
npx create-video --yes --blank --no-tailwind my-video
npx create-video@latest

SKILL.md:123-161:

bash
npm i -g clawhub
pnpm add -g clawhub

openclaw skills install remotion-video-toolkit

npx clawhub@latest install remotion-video-toolkit --force

npx skills add remotion-dev/skills

SKILL.md:339-341:

bash
pip install -e video-use/helpers
pip install requests librosa matplotlib pillow numpy

Technical Analysis

The documentation instructs users or AI agents to download and execute npm packages, Python packages, and third-party Skills without pinning exact versions, reviewed commit hashes, or integrity checks.

Commands using npx ...@latest explicitly resolve a mutable registry release at execution time. Other commands omit versions entirely, allowing package resolution to change after this Skill has been reviewed. The --force option additionally bypasses normal installation safeguards. Installing external Skills imports remotely maintained agent instructions that are outside the audited project and may change independently.

npm packages can execute lifecycle scripts during installation, and packages invoked through npx can execute code immediately. Python packages can also execute build or installation logic. Consequently, compromise of an upstream package, publishe ...[truncated 1988 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every npm and Python dependency to an exact reviewed version rather than using latest or an omitted version.
  2. Pin repository-based Skill installations to immutable commit hashes whenever the installation tooling supports this.
  3. Commit and enforce package lockfiles, including npm integrity metadata, for generated or companion projects.
  4. Remove --force from installation instructions unless its necessity is documented and the user explicitly approves its use.
  5. Require explicit user confirmation before installing any external package or Skill.
  6. Review third-party Skill contents before loading them into an agent session.
  7. Prefer locally vendored and audited helper scripts over runtime retrieval of mutable external content.
  8. Use isolated environments, such as containers, virtual environments, or restricted non-privileged accounts, for package installation and media processing.
  9. Disable package lifecycle scripts during initial inspection where practical, then enable only those required by reviewed packages.
  10. Add provenance or checksum verification and periodically audit pinned dependencies for known vulnerabilities.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (20)

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The README instructs users to execute npx clawhub@latest install 16miku/auto-remotion, which pulls and runs remote code at install time without pinning a reviewed version. If the upstream package is compromised or a breaking release is published, users of the skill may execute unexpected code on their machines.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The README tells users to run npx create-video --yes --blank --no-tailwind my-video without pinning the package version, so the command may fetch and execute whatever the latest published scaffold tool is at the time. That creates a supply-chain risk and undermines reproducibility for users following the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README promotes automated transcription and video understanding using third-party services such as ElevenLabs Scribe, but it does not warn that screen recordings may contain secrets, internal product details, customer data, or other sensitive material. In this skill's context, users are specifically uploading recordings and demos, which makes accidental data disclosure materially more likely.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The skill instructs running npx create-video without pinning a version, which causes code to be fetched and executed from the registry at runtime. If the upstream package changes, is compromised, or a malicious version is published, an agent or user following the skill may execute unreviewed code with local permissions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

This is another occurrence of unpinned npx create-video, with the same supply-chain risk profile: it resolves the latest package at execution time and immediately runs it. In an agent context, this is riskier because the command may be executed non-interactively and without human review.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The unpinned npx create-video command exposes users to upstream package substitution or compromise. Because the skill presents this as a standard setup step, it normalizes executing remote code without integrity controls.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

This non-interactive npx create-video command is especially sensitive because automation flags reduce opportunities for user inspection while still executing fetched code. A compromised package could run arbitrary install-time or startup logic on the host.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest says the skill is not applicable when AI-generated video imagery is needed and only handles editing/compositing existing footage. However, the environment setup section lists the Remotion --prompt-to-video template as an available option, which is specifically for AI text-to-video generation and broadens the described scope.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
85% confidence
Finding

npx clawhub@latest install ... --force executes a latest-tag package from the network and forces installation behavior, which increases supply-chain and unintended-change risk. In a skill ecosystem, installing additional skills via an unpinned package can expand the trusted codebase without review.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

npx skills add ... is another unpinned runtime execution path that may pull and execute arbitrary package code from the registry. Because it installs skills for an agent, compromise here can affect future agent behavior and broaden persistence of the risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

This duplicate unpinned npx skills invocation carries the same remote-code-execution and supply-chain exposure as the previous finding. The skill treats it as routine setup, which may lead agents to execute it automatically.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

A further unpinned npx skills command again relies on resolving the latest package state at runtime. Repetition of this pattern increases the chance users will follow the least safe path and makes the document less deterministic and auditable.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
76% confidence
Finding

npx remotion --version is lower risk than install commands because it is a version check, but it still may fetch and execute an unpinned package if not already installed. That means it remains a supply-chain execution vector, though with less direct operational impact than scaffold or install steps.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill recommends network-based transcription and TTS workflows using external services without explicit privacy, consent, or data-handling warnings. Video/audio transcripts can contain sensitive business, personal, or customer information, so silently sending derived content to third parties creates a real confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation defines stage six specifically as Chinese dubbing and selects Chinese neural voices as the default workflow, without presenting language choice or requiring user opt-in. This is a natural-language locale policy issue because it constrains output language by default rather than allowing the user's preference.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The render command uses unpinned npx remotion, which can fetch and execute whichever version is current at render time. Rendering often processes local media and project files, so a compromised package could access or exfiltrate sensitive assets during a common workflow step.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The Hard Rules section explicitly states 不在 skill 目录写任何输出 and to write outputs under <videos_dir>/edit/. Later, the project structure section defines generated artifacts such as edit scripts, transcripts, PNGs, and helper scripts under project/work/projects/{project-id}/, which contradicts the earlier stated output-location rule unless that path is guaranteed external to the skill directory.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

SQP-3 applies to all file types, including JSON. All prompts and expected outputs are written in Chinese, and the expected behavior appears to assume Chinese-language operation without offering an opt-in or documenting that this is intentionally a region- or language-specific skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The primary skill description is presented in Chinese, which effectively forces a specific language for users reading the skill documentation. The file does not offer an alternative language, user opt-in, or any explanation that the skill is intentionally region- or locale-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This is a JSON manifest-like file, so SQP-1 applies. The note says '文字转视频 ≠ 录屏转宣传片' as a should-not-trigger distinction, but the file does not define explicit trigger phrases, activation conditions, or clearer exclusion criteria beyond this single contrast, which can leave invocation scope ambiguous.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.