Back to skill

Security audit

人工级视频字幕翻译

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed video-subtitle workflow that uses local files, provider credentials, and network services in ways that match its stated purpose.

Before installing, be comfortable with the selected video's audio being uploaded to OkFile, a temporary public audio URL being sent to Alibaba Fun-ASR, and subtitle text being processed by Alibaba qwen-mt-plus or the current Agent model. Keep API keys in the local .env file only, and use this only for videos you are allowed to send to those providers.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.