Back to skill

Security audit

DaVinci Auto Editor

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its video-editing purpose, but it needs review because it can send an API key and detailed local media path metadata to a cloud service, and the sample endpoint uses unencrypted HTTP.

Install only if you trust the cloud editing service and configure an HTTPS API endpoint. Avoid running it on sensitive media folders unless you are comfortable sending filenames, paths, sizes, timestamps, task metadata, and execution reports to that service. Do not use the sample HTTP endpoint with a real API key; rotate any key already sent over HTTP, and prefer a pinned package version instead of unversioned npx.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
examples/config.example.json:2
Finding

Bearer API Credentials and Media Metadata Transmitted Over Plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: examples/config.example.json:2; scripts/index.js:180-199
Vulnerability Type: Plaintext transmission of credentials and sensitive metadata
Risk Level: High

Vulnerable Code

examples/config.example.json:2:

json
"api_base_url": "http://43.137.46.105:8787",

scripts/index.js:180-199:

js
async request(method, endpoint, body) {
  const url = new URL(endpoint.replace(/^\//, ''), this.baseUrl);
  const controller = new AbortController();
  const timer = setTimeout(() => controller.abort(), this.timeoutMs);
  try {
    const response = await fetch(url, {
      method,
      headers: {
        'content-type': 'application/json',
        'authorization': `Bearer ${this.apiKey}`,
        'user-agent': 'davinci-auto-editor/0.2.0'
      },
      body: body === undefined ? undefined : JSON.stringify(body),
      signal: controller.signal
    });
    const text = await response.text();
    const parsed = text ? JSON.parse(text) : {};

Technical Analysis

The example configuration directs users to an API endpoint using unencrypted HTTP and a bare IP address. The API client accepts this URL without validating that the protocol is HTTPS. It then transmits the configured API key in a bearer authorization header and serializes request data into the HTTP body.

Because HTTP provides neither confidentiality nor server authentication, an attacker with a network position can inspect or modify this traffic. Relevant attacker positions include a compromised Wi-Fi access point, malicious proxy, local network adversary, or compromised upstream router. The use of an Authorization: Bearer header means interception directly discloses a reusable credential.

The same channel carries media inventory information and cloud editing requests. A man-in-the-middle attacker could therefore obtain both credentials and private project metadata, inject a fo ...[truncated 1417 chars]

Remediation
View remediation

Remediation Suggestions

  1. Enforce HTTPS during configuration validation:
    js
    const apiUrl = new URL(config.api_base_url);
    if (apiUrl.protocol !== 'https:') {
      throw new Error('api_base_url must use HTTPS');
    }
    
  2. Permit plaintext HTTP only through an explicit development-only option restricted to loopback addresses such as 127.0.0.1 or localhost.
  3. Replace the example endpoint with a trusted HTTPS URL under a verified domain.
  4. Do not recommend bare-IP endpoints unless certificate identity and ownership can be securely verified.
  5. Rotate any API key that has already been sent to the documented HTTP endpoint.
  6. Apply narrowly scoped permissions, short expiration periods, revocation support, and server-side rate limits to API keys.
  7. Consider certificate pinning or equivalent endpoint verification where the deployment threat model requires protection from compromised trust infrastructure.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/index.js:143
Finding

Unnecessary Disclosure of Absolute Local Filesystem Paths to the Cloud API

Content
View full analysis

Vulnerability Details

File Location: scripts/index.js:143-153, scripts/index.js:38-41, and scripts/index.js:233-241
Vulnerability Type: Excessive collection and remote disclosure of local filesystem metadata
Risk Level: Medium

Vulnerable Code

scripts/index.js:143-153:

js
results.push({
  id: crypto.createHash('sha1').update(fullPath).digest('hex').slice(0, 12),
  name: entry.name,
  extension,
  kind: classifyMedia(extension),
  absolutePath: fullPath,
  relativePath: path.relative(rootDir, fullPath).replace(/\\/g, '/'),
  sizeBytes: stats.size,
  modifiedAt: stats.mtime.toISOString()
});

scripts/index.js:38-41:

js
await api.post(`/v1/tasks/${encodeURIComponent(taskId)}/material-index`, {
  materials,
  summary: buildMaterialSummary(materials)
});

scripts/index.js:233-241:

js
let response = await api.post(`/v1/tasks/${encodeURIComponent(taskId)}/plan`, {
  projectType: config.project_type,
  aspectRatio: config.aspect_ratio,
  templateId: config.template_id,
  subtitleMode: config.subtitle_mode,
  musicPolicy: config.music_policy,
  pacePolicy: config.pace_policy,
  outputMode: config.output_mode,
  materials
});

Technical Analysis

The recursive scanner stores each media file’s absolute path in the same object used for remote API requests. The complete materials array is uploaded both to the material-index endpoint and to the planning endpoint.

An absolute path is necessary for subsequent local EDL generation, but it is not necessary for remote clip identification. Opaque material IDs and sanitized relative paths are sufficient for correlating cloud plan segments with local files. Combining local-only state and remote-transfer state in one object violates data-minimization and least-disclosure principles.

Absolute paths may reveal operating-system usernames, organization names, customer or campaign identifiers, mo ...[truncated 1681 chars]

Remediation
View remediation

Remediation Suggestions

  1. Separate local material records from the remote API representation.
  2. Retain absolutePath only in local process memory:
    js
    function toRemoteMaterial(material) {
      return {
        id: material.id,
        name: material.name,
        extension: material.extension,
        kind: material.kind,
        relativePath: material.relativePath,
        sizeBytes: material.sizeBytes
      };
    }
    
  3. Create a sanitized array before each API request:
    js
    const remoteMaterials = materials.map(toRemoteMaterial);
    
  4. Send remoteMaterials, rather than materials, to both /material-index and /plan.
  5. Remove modification timestamps unless the cloud planning service has a documented operational need for them.
  6. Prefer opaque, random local identifiers instead of deriving IDs from absolute paths.
  7. Clearly document every metadata field transmitted to the cloud and obtain explicit user consent before uploading the inventory.
  8. Apply server-side retention limits, access controls, audit logging, and deletion mechanisms to uploaded metadata.

T08 · Insecure Dependencies

Warning
Location
README.md:33
Finding

Documentation Recommends Unpinned Package Retrieval and Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: README.md:33-35
Vulnerability Type: Mutable and unpinned package execution from a third-party registry
Risk Level: Medium

Vulnerable Code

README.md:33-35:

bash
npx davinci-auto-editor --config ./examples/config.example.json

Technical Analysis

The documentation recommends executing the package through npx without specifying an exact version or verified artifact. If the package is not already installed locally, npx may resolve and download the package version currently selected by the registry.

This creates a mutable supply-chain boundary: the code executed by a future user may differ from the version reviewed in this audit. Package-maintainer account compromise, registry compromise, malicious publication, or an unsafe later release could cause arbitrary JavaScript to run on the user’s system.

The reviewed package.json contains no third-party runtime dependencies, which reduces the present dependency surface. However, unpinned registry execution still delegates trust to mutable package metadata and future package contents.

Attack Path

  1. An attacker compromises the package publisher account, registry entry, or release process.
  2. The attacker publishes a malicious version under the same package name.
  3. A user follows the README and invokes the unversioned npx command.
  4. npx resolves and downloads the registry-selected package version.
  5. The package entry point executes with the invoking user’s operating-system permissions.
  6. Malicious package code can access files and credentials available to that user, make network requests, or alter user-writable system state.

Impact Assessment

Successful exploitation permits arbitrary code execution with the privileges of the user invoking npx. The potential scope includes readable project files, environment variables, configuration files, API credentials, user-writable files, and n ...[truncated 197 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the documented command to an exact reviewed version:
    bash
    npx --yes davinci-auto-editor@0.2.1 --config ./examples/config.example.json
    
  2. Prefer installation from a signed and verified release artifact.
  3. Publish checksums or provenance attestations for releases and explain how users should verify them.
  4. For managed deployments, use a lockfile and an internal allowlisted registry or artifact mirror.
  5. Protect publisher accounts with phishing-resistant multi-factor authentication and restricted release tokens.
  6. Avoid instructing users to run package-management commands with administrator or root privileges.
  7. Establish a release review process so the pinned version in the documentation is updated only after security verification.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The README instructs users to run the package via npx davinci-auto-editor without pinning a specific version. That causes execution of whatever version is currently published under that name at install time, which increases supply-chain risk if a malicious update, account compromise, or typo-squatted package is introduced. In the context of a local media-processing skill that handles filesystem access and API keys, arbitrary package changes are more dangerous because the code runs on the user machine with access to local media and cloud credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly describes scanning a local material directory, calling multiple cloud task endpoints, downloading a plan, and sending an execution report, but it does not clearly warn users that local media metadata, filenames, paths, or other project information may be transmitted to remote services. This creates a privacy and data-governance risk because users may unintentionally expose sensitive production data, client names, or filesystem structure to a third party. The skill context makes this more significant because the tool is designed around local media ingestion and cloud processing, so data transmission is a core behavior rather than an incidental one.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares capabilities that involve network access and likely use of environment/config secrets, but it does not declare any explicit tool scope or permissions boundary. That increases the risk of overbroad execution, silent data egress, and use of sensitive credentials without clear user consent or runtime restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs recursive scanning of a local media directory and reporting the resulting index to a cloud API, but the description does not clearly warn the user that local media metadata will be collected and transmitted off-device. In this context, filenames, paths, timestamps, embedded metadata, and project structure can reveal sensitive personal or business information, making the omission materially risky.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest explicitly states that the skill will scan local media and use a cloud editing API, but it does not provide a clear user-facing warning that local file information and possibly media-derived metadata will be transmitted off-device. In a skill that processes user media, this omission can cause unintentional disclosure of sensitive content, filenames, paths, or metadata to a remote service without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This skill recursively scans local media and uploads detailed metadata, including absolute file paths, relative paths, filenames, sizes, and modification times, to a cloud API without any explicit consent prompt or prominent disclosure. In this context, the skill operates on a user's workstation and local creative assets, so silent transmission of workstation path structure and media inventory materially increases privacy and confidentiality risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The import guide states that the package 'does not include the full cloud plan', but earlier code constructs importPlan from the cloud plan and writes it to resolve-import.json. While not necessarily the raw API response, the package does include cloud-plan-derived execution details, so the documentation materially understates what is being saved locally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The operational instructions are presented in Chinese ('使用这个 skill 时,按下面顺序执行') with no indication that the skill supports other languages or that Chinese is required for a region-specific purpose. This creates a language policy issue because it imposes a locale/language constraint without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest requires an API key and network access, which indicates authenticated outbound communication, but it does not clearly disclose how credentials are used or that the skill will make external requests. While this is not direct evidence of credential theft, the lack of transparency around secret handling and network behavior increases the risk of users supplying sensitive credentials without understanding exposure or trust boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The script requires api_key and uses it for Authorization headers, but there is no nearby comment, help text, or runtime notice explaining that a sensitive credential must be provided and will be used for outbound requests. This is a code-file warning gap under the credential-access criterion.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access, suspicious.install_untrusted_source

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/index.js:14

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
examples/config.example.json:2