Back to skill

Security audit

Product Description to Ad

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to use Revid to generate videos from user-provided content, which is expected for its purpose and not evidence of hidden or harmful behavior.

Before installing, treat anything sent to Revid as leaving your local environment. Avoid uploading confidential product plans, unreleased creative assets, or regulated data unless you are comfortable with Revid processing it and your API account terms allow it.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs sending user-supplied product descriptions and optional media files to the external service `www.revid.ai` without an explicit disclosure or consent step. This creates a data handling and privacy risk because users may provide confidential marketing plans, unreleased product details, or proprietary images without realizing they will leave the local agent environment.

Static analysis

No suspicious patterns detected.