Back to skill

Security audit

subtitle-generator

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent subtitle generator, but it also automatically installs persistent dependencies and directs broad background cleanup and notification actions that should be reviewed before use.

Review this skill before installing. It should ask before first-run package installation, pin its dependencies, limit cleanup to skill-owned temporary files, track only its own process IDs, and make notifications explicitly opt-in with clear disclosure of what file names or paths are sent.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (22)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill directs the agent to execute shell commands, create environments, install dependencies, write files beside the source video, and clean temporary files, yet it declares no explicit tool scope or permission boundary. This creates an overbroad execution surface where the agent may invoke powerful capabilities without clear user-visible constraints or policy enforcement.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description lists many activation phrases, including broad terms like "subtitle", "subtitles", "caption", "transcription", and "speech to text" without any exclusion conditions or context limits. In a manifest file, this can cause unintended invocation for general conversation or unrelated tasks involving captions or transcription.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that importing the engine may automatically create a virtual environment and install packages on first use, but it does not present this as a prominent user warning or require consent. Silent environment creation and package installation materially change the host system and introduce supply-chain and execution risk beyond what a user may expect from 'generate subtitles'.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill mandates process killing, AI wake-up via a system event command, background execution, file copying, and /tmp cleanup as part of its normal flow. These system-level orchestration actions exceed the core purpose of subtitle generation and can affect unrelated processes or files if implemented loosely or triggered on attacker-controlled inputs.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs the AI to use a cross-channel messaging capability and explicitly optimize for automatic routing to whatever chat platform the user is on. Subtitle generation does not require outbound messaging behavior, so this expands the skill from local media processing into user-contact automation, increasing the risk of unsolicited notifications, channel misuse, or abuse if outputs are spoofed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill directs copying subtitle files into the source video's directory and cleaning files from /tmp without prominently warning the user beforehand. These file-system side effects can overwrite expectations, remove data needed by other processes, or lead to unintended modification/deletion if cleanup boundaries are not strict.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · engines/__init__.py (reported line 46)May include surrounding context.

python
def _check_venv_packages(pip_path: Path) -> bool:
    """Check if the venv has packages installed by running pip list."""
    try:
        result = subprocess.run(
            [str(pip_path), "list", "--format=json"],
            capture_output=True,
            text=True,

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The engine loader performs automatic virtual environment creation, package inspection, module path manipulation, and pip-based installation during normal operation. For a subtitle/transcription skill, this is an unjustified capability expansion that creates opportunities for unauthorized code execution, supply-chain risk, and persistent modification of the host environment.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
83% confidence
Finding

The code resolves and executes whichever 'python' or 'python3' appears first in PATH to create a virtual environment. In agent or multi-tenant environments, PATH can be influenced, allowing execution of an unexpected interpreter or wrapper and expanding the skill from transcription into arbitrary environment setup behavior.

Content

Scanner excerpt · engines/__init__.py (reported line 94)May include surrounding context.

python
python_cmd = shutil.which("python") or shutil.which("python3") or "python3"
        else:
            python_cmd = shutil.which("python3") or shutil.which("python") or "python3"
        result = subprocess.run(
            [python_cmd, "-m", "venv", str(venv_path)],
            capture_output=True,
            text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
91% confidence
Finding

This code automatically runs pip install at runtime, causing network-capable package installation and execution of package setup/build logic. That exceeds the expected scope of a subtitle-generation skill and can lead to supply-chain compromise or unauthorized system modification if requirements or package sources are tampered with.

Content

Scanner excerpt · engines/__init__.py (reported line 109)May include surrounding context.

python
# Step 3: Install requirements.txt
    print("[Setup] Installing dependencies...")
    try:
        result = subprocess.run(
            [str(pip_path), "install", "-r", str(requirements_path)],
            capture_output=True,
            text=True,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code prints Chinese-only status messages at L33 and L44, which imposes a specific language on users. Under the policy, language-specific behavior is a violation unless the skill offers user opt-in or clearly documents a justified locale constraint.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 160)May include surrounding context.

md
"ffmpeg 未找到,请先安装 ffmpeg:\n"
            "  Windows: winget install ffmpeg  或  https://ffmpeg.org/download.html\n"
            "  macOS:  brew install ffmpeg\n"
            "  Linux:  sudo apt install ffmpeg  或  sudo yum install ffmpeg"
        )

# Add skills subtitle-generator to path for imports

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/main.py (reported line 45)May include surrounding context.

python
"ffmpeg 未找到,请先安装 ffmpeg:\n"
            "  Windows: winget install ffmpeg  或  https://ffmpeg.org/download.html\n"
            "  macOS:  brew install ffmpeg\n"
            "  Linux:  sudo apt install ffmpeg  或  sudo yum install ffmpeg"
        )

# Add skills subtitle-generator to path for imports

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The subtitle-generation skill includes an unrelated outbound notification pathway that can trigger an external tool and, per comments, indirectly cause Telegram messages. In a skill expected to do local media processing, this creates an unnecessary side-effect channel that can leak filenames, paths, error details, or processing activity outside the immediate task boundary.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/main.py (reported line 63)May include surrounding context.

python
# Last resort: try common nvm path (Linux/WSL)
        openclaw_cmd = str(Path.home() / ".nvm/versions/node/v24.14.0/bin/openclaw")
    try:
        result = subprocess.run(
            [openclaw_cmd, "system", "event", "--text", message, "--mode", "now"],
            capture_output=True,
            text=True,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code emits user-facing status and error text in Chinese, such as the extraction message at L026, and similar strings appear throughout the file. The policy forbids forcing a specific language without user opt-in, and this file does not provide a locale selection mechanism or justification for a Chinese-only interface.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code prints user-visible progress messages in Chinese at L33 and L47, which imposes a specific language on users without any opt-in or configuration. This matches the language/locale policy concern for natural-language content in code.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency faster-whisper is unpinned, so future installs may resolve to different versions with breaking changes or newly introduced malicious/compromised releases. This creates supply-chain risk and hurts reproducibility, especially for a skill that processes user-provided audio and may run in automated environments.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
faster-whisper
openai-whisper
ffmpeg-python

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency openai-whisper is unpinned, allowing installs to pull whatever version is current at installation time. That increases exposure to supply-chain compromise, unexpected behavior changes, and non-reproducible builds in a transcription-focused skill.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
faster-whisper
openai-whisper
ffmpeg-python

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency ffmpeg-python is also unpinned, which means installations may consume unexpected upstream releases or compromised packages. Because this library interfaces with media-processing workflows, inconsistent dependency resolution can affect both security posture and runtime stability.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
faster-whisper
openai-whisper
ffmpeg-python

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The user-facing usage text and examples present parameters and surrounding instructions in Chinese while other interface text remains in English, effectively imposing a mixed locale without opt-in or configuration. This can violate a language/locale policy when the skill does not explicitly let the user choose the interface language.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The docstring describes only a local system event, while adjacent comments state that the event will wake the main session and lead to Telegram notifications. This mismatch can mislead reviewers and users about the true data flow, reducing transparency around external communication and making unintended disclosure harder to detect.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.