Security audit
人工级视频字幕翻译
Security checks across malware telemetry and agentic risk
Overview
This skill is a disclosed video-subtitle workflow that uses local files, provider credentials, and network services in ways that match its stated purpose.
Before installing, be comfortable with the selected video's audio being uploaded to OkFile, a temporary public audio URL being sent to Alibaba Fun-ASR, and subtitle text being processed by Alibaba qwen-mt-plus or the current Agent model. Keep API keys in the local .env file only, and use this only for videos you are allowed to send to those providers.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
