Back to skill

Security audit

video-en2zh-dub

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent English-to-Chinese dubbing workflow, but it under-discloses that subtitle text is sent to Microsoft through edge-tts despite claiming the stack is offline.

Install only if you are comfortable sending translated subtitle text to Microsoft via edge-tts. Avoid using it on confidential, regulated, or private video content unless that external TTS data flow is acceptable, and check for existing output files before running because ffmpeg commands may overwrite them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (17)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README states the stack is entirely offline/free, but the same document later admits edge-tts depends on Microsoft's online service. This is a security-relevant misrepresentation because users may process sensitive video/audio content under the false assumption that no data leaves their environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README does not clearly warn, at the point of use, that the TTS step transmits subtitle or script content to an external Microsoft service. In a dubbing workflow, subtitles may contain confidential business, personal, or regulated information, so silent cloud transmission creates a meaningful privacy and compliance risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill clearly instructs the agent to read and write local files and inspect the environment, yet it declares no explicit tool scope or permission boundaries. That creates an authorization ambiguity where the runtime may grant broader file or environment access than users expect, increasing the risk of unintended data exposure or modification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is explicitly defined as an English-to-Chinese dubbing pipeline and the instructions require producing Chinese subtitles and Chinese speech. This is a natural-language locale constraint that does not present the user with a language choice or opt-in within the skill description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instructions mandate ffmpeg's -y flag, which will overwrite existing output files without prompting, but the skill does not require a user-facing warning before destructive writes. In a directory containing prior output.mp4, output.mp3, or similarly named artifacts, this can silently destroy user data or replace results from earlier runs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all guidance and operational instructions exclusively in Chinese, and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document is entirely framed around producing Chinese dubbing and includes prescriptive guidance such as limiting Chinese character counts and optimizing '中文解说' timing. There is no indication that the language choice is optional or user-selected, which can violate a language/locale policy when a skill imposes a specific language by default.

Content

No source excerpt is available for this finding.

Tainted flow: 'value' from os.environ.get (line 119, credential/environment) → open (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/check_env.py (reported line 125)May include surrounding context.

python
return

    try:
        with open(value, "a"):
            pass
        print(f"  OK    SSLKEYLOGFILE {value}(实测可写)")
        return

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring, CLI help text, and runtime messages are all written in Chinese, which imposes a specific language on users. Under the policy, locale/language constraints should be opt-in or clearly justified as region-specific; this file provides neither.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s docstring, user-facing error messages, and argument descriptions are written in Chinese throughout, while the script processes English audio and does not provide any user opt-in or alternate locale. This creates a natural-language locale policy concern because the skill effectively enforces a specific interface language without documented choice or region-specific justification.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE (reported line 12)May include surrounding context.

text
permit persons to whom the Software is furnished to do so.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED,
INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A
PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT
HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language content in this requirements file is entirely in Chinese, including installation guidance and troubleshooting notes. For a general-purpose dependency file, this imposes a language constraint on users without opt-in or a documented region-specific justification, matching the language/locale policy concern.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

Using an unpinned dependency range for openai-whisper allows future versions to be installed without review, which can introduce breaking changes or malicious/suspect upstream updates through the software supply chain. In a media-processing skill that depends on external packages and native/transitive dependencies like torch/ffmpeg-adjacent tooling, this increases exposure to compromised releases and reduces build reproducibility.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
# Python 依赖,推荐安装顺序见文件末尾

openai-whisper>=20230124
edge-tts>=7.0.0
pysrt>=1.1.2
pydub>=0.25.1

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

Using edge-tts>=7.0.0 permits automatic installation of newer unreviewed releases, creating a supply-chain risk and making builds non-reproducible. Because this skill processes user-supplied media and synthesizes audio through third-party code paths, an unsafe upstream release could affect integrity or availability of the environment.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
# Python 依赖,推荐安装顺序见文件末尾

openai-whisper>=20230124
edge-tts>=7.0.0
pysrt>=1.1.2
pydub>=0.25.1

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

pysrt>=1.1.2 is unpinned, so future releases may be pulled in unexpectedly, weakening reproducibility and opening a smaller but real supply-chain attack surface. While this package is less inherently sensitive than core model/runtime dependencies, subtitle parsing still operates on external content and should be tightly version-controlled.

Content

Scanner excerpt · requirements.txt (reported line 5)May include surrounding context.

text
openai-whisper>=20230124
edge-tts>=7.0.0
pysrt>=1.1.2
pydub>=0.25.1

# Python 3.13 起标准库移除了 audioop,而 pydub 依赖它。

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

pydub>=0.25.1 allows unreviewed future versions to enter the environment, creating supply-chain and stability risk. In this skill, pydub participates in audio handling and interfaces with ffmpeg/ffprobe-related workflows, so unexpected upstream changes or compromise could impact media processing integrity or cause denial of service.

Content

Scanner excerpt · requirements.txt (reported line 6)May include surrounding context.

text
openai-whisper>=20230124
edge-tts>=7.0.0
pysrt>=1.1.2
pydub>=0.25.1

# Python 3.13 起标准库移除了 audioop,而 pydub 依赖它。
# 在 3.13+ 上不装这个包,import pydub 会直接失败。

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains its primary documentation and all console messaging in Chinese, which imposes a specific language on users without any opt-in or fallback. Under the policy for natural-language violations, forcing a locale/language without user choice is reportable unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.