Back to skill

Security audit

Video-Generator

Security checks for vulnerabilities and agentic risk

Overview

This video-generation skill is coherent, but it asks agents to expose a local development server publicly and run mutable npm tooling without enough scoping or user control.

Install only if you are comfortable with agents running npm tooling and using Firecrawl. Before use, pin npm package versions, prefer locked local dependencies, require explicit approval before any Cloudflare tunnel, add authentication or short-lived access controls, and do not send private or internal URLs to Firecrawl.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
scripts/remotion.sh:10
Finding

Execution of Unpinned npm Packages Through npx

Content
View full analysis

Vulnerability Details

File Location: scripts/remotion.sh:8-10
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: High

Vulnerable Code:

bash
init)
  PROJECT_NAME="${1:?init <name>}"
  npx --yes create-video@latest "$PROJECT_NAME"
  ;;

Technical Analysis

The script invokes create-video@latest through npx --yes. The latest tag is mutable and does not identify a specific reviewed package version or integrity hash. The --yes option suppresses the interactive installation prompt, allowing npm to download and execute the currently published package without user confirmation.

An npm package executed through npx may run its command-line entry point and installation lifecycle scripts with the privileges of the user running the skill. Consequently, the effective code executed by this reviewed script can change after the audit if the package is compromised, transferred to a malicious maintainer, or receives an unsafe release.

The same script also invokes npx remotion render at line 21. If Remotion is unavailable locally, npx may resolve and download a package dynamically rather than using a known, locked dependency.

Attack Path

  1. An attacker compromises the create-video npm package, its maintainer account, or its release process.
  2. The attacker publishes a malicious version under the mutable latest tag.
  3. A user or agent invokes scripts/remotion.sh init.
  4. npx --yes downloads the malicious package without an interactive confirmation.
  5. npm executes the package entry point or applicable lifecycle scripts.
  6. The malicious package executes arbitrary commands under the invoking user's account.

Impact Assessment

Successful exploitation provides arbitrary code execution with the permissions of the account running the skill. The malicious dependency could read or alter accessible project files, environment variables, source-code cr ...[truncated 295 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace mutable tags such as latest with an exact, reviewed version.
  • Declare the required tooling in a committed package.json and lock it with package-lock.json.
  • Install dependencies using npm ci so resolution is reproducible and fails when the lockfile is inconsistent.
  • Execute the locked local binary, such as npx --no-install create-video, rather than permitting dynamic downloads.
  • Use npx --no-install remotion render for rendering and fail if the expected local package is absent.
  • Review npm provenance and integrity metadata before version updates.
  • Disable package lifecycle scripts where compatible with the toolchain, or perform installation in an isolated environment with minimal filesystem access, credentials, and network permissions.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:15
Finding

Unauthenticated Public Exposure of the Remotion Development Server

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:15-16
Vulnerability Type: Unsafe public exposure of a development service
Risk Level: Medium

Vulnerable Instructions:

text
5. Run dev server (Remotion Studio)
6. Expose via Cloudflare tunnel
7. Share public URL

Technical Analysis

The documented workflow directs the agent to start Remotion Studio, expose it through a Cloudflare tunnel, and share the resulting public URL. It does not require authentication, authorization, an access policy, an expiration time, network restrictions, or a review of the content exposed by the development server.

Development servers are generally intended for trusted development environments and can expose previews, project assets, source-related metadata, or development-only endpoints. A tunnel makes the service reachable beyond the local host and bypasses the protection otherwise provided by binding the service only to a local interface. The exact reachable functionality depends on the generated Remotion project and tunnel configuration, but the instructions do not establish any compensating controls.

Attack Path

  1. The agent creates a Remotion project containing video assets or other project data.
  2. The agent starts the Remotion Studio development server.
  3. The agent creates a public Cloudflare tunnel as required by the workflow.
  4. The public URL is shared, forwarded, logged, indexed, or otherwise disclosed to an unintended party.
  5. The unintended party connects to the development service without an authentication requirement.
  6. The party accesses any project content or development functionality exposed by that specific Studio instance.

Impact Assessment

Exploitation can disclose video previews, project assets, or other information served by the development environment. It may also expose development functionality to unauthorized users, with the precise modification or execution capabilities de ...[truncated 276 chars]

Remediation
View remediation

Remediation Suggestions

  • Keep Remotion Studio bound to localhost by default and do not create a public tunnel unless the user explicitly requests remote review.
  • Prefer exporting a static, sanitized preview rather than exposing a live development service.
  • If remote access is required, enforce Cloudflare Access or an equivalent identity-aware authentication policy.
  • Restrict access to explicitly approved identities and apply short expiration periods.
  • Review the project for secrets, private assets, source maps, and development-only endpoints before exposure.
  • Generate an unguessable, short-lived sharing URL and avoid publishing it in persistent or public channels.
  • Automatically terminate the tunnel immediately after the review session.
  • Run the development server in an isolated, least-privileged environment without unnecessary credentials or filesystem access.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The workflow instructs the agent to expose a dev server through a Cloudflare tunnel and share a public URL, but the skill description does not warn the user that local work-in-progress content may become internet-accessible. In this context, that omission is risky because a development server may expose source, debug interfaces, unreviewed assets, or internal project details to external parties.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
85% confidence
Finding

Using npx remotion render without pinning an explicit package version can cause the skill to fetch and execute whatever package version is current at runtime. This creates a supply-chain risk and reduces reproducibility, especially in an agent workflow that may run unattended and execute package manager commands automatically.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The hardcoded external endpoint confirms that all scraped content requests are sent to a third-party service outside the local trust boundary. That means any operator-provided URL, including potentially sensitive internal targets, may be disclosed externally, making this more than a harmless network call. In this skill, the context does not mitigate the risk because the script has no validation or guardrails around what can be sent.

Content

Scanner excerpt · scripts/firecrawl.sh (reported line 11)May include surrounding context.

sh
exit 1
fi

curl -s -X POST 'https://api.firecrawl.dev/v1/scrape' \
  -H 'Content-Type: application/json' \
  -H "Authorization: Bearer ${FIRECRAWL_API_KEY}" \
  -d "{\"url\":\"$URL\",\"formats\":[\"markdown\",\"extract\",\"screenshot\"]}"

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The hardcoded external endpoint confirms that all scraped content requests are sent to a third-party service outside the local trust boundary. That means any operator-provided URL, including potentially sensitive internal targets, may be disclosed externally, making this more than a harmless network call. In this skill, the context does not mitigate the risk because the script has no validation or guardrails around what can be sent.

Content

Scanner excerpt · scripts/firecrawl.sh (reported line 11)May include surrounding context.

sh
exit 1
fi

curl -s -X POST 'https://api.firecrawl.dev/v1/scrape' \
  -H 'Content-Type: application/json' \
  -H "Authorization: Bearer ${FIRECRAWL_API_KEY}" \
  -d "{\"url\":\"$URL\",\"formats\":[\"markdown\",\"extract\",\"screenshot\"]}"

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The script executes an unpinned package via npx --yes create-video@latest, which fetches and runs whatever code is currently published under that package name. This creates a supply-chain risk: a compromised upstream package, malicious publish, or breaking update could execute arbitrary code on the user's machine during init.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The script invokes npx remotion render without pinning the package version, so npx may resolve and execute a package version that is not explicitly controlled by this skill. If the package is absent locally or a different version is fetched, this can lead to arbitrary code execution through a compromised or unexpected upstream package.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.