Back to skill

Security audit

Ffmpeg Master Pro

Security checks for vulnerabilities and agentic risk

Overview

This video-processing skill is coherent overall, but it needs review because some documented workflows can silently overwrite files and one referenced code example uses unsafe Python evaluation on media metadata.

Review before installing. Use it only on media files you intend to process, choose output paths carefully, avoid or remove commands that use -y unless overwriting is intentional, and do not copy the eval() frame-rate example into runnable code. Expect local hardware probes for GPU acceleration and a small user config directory for presets.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
references/detailed_workflows.md:40
Finding

Unsafe Evaluation of FFprobe Frame-Rate Metadata

Content
View full analysis

Vulnerability Details

File Location: references/detailed_workflows.md:40-65
Vulnerability Type: Arbitrary Python expression evaluation
Risk Level: Medium

Vulnerable Code

python
import subprocess
import json

def analyze_video(input_file):
    cmd = [
        'ffprobe',
        '-v', 'quiet',
        '-print_format', 'json',
        '-show_format',
        '-show_streams',
        input_file
    ]

    result = subprocess.run(cmd, capture_output=True, text=True)
    metadata = json.loads(result.stdout)

    # Extract key information
    video_stream = next(s for s in metadata['streams'] if s['codec_type'] == 'video')
    audio_stream = next(s for s in metadata['streams'] if s['codec_type'] == 'audio')

    return {
        'format': metadata['format']['format_name'],
        'codec': video_stream['codec_name'],
        'width': int(video_stream['width']),
        'height': int(video_stream['height']),
        'fps': eval(video_stream['r_frame_rate']),

Technical Analysis

The primary documented video-analysis workflow evaluates the r_frame_rate value returned by FFprobe using Python's eval(). A normal value is a rational expression such as 30000/1001, but eval() accepts arbitrary Python expressions rather than limiting the input to numeric fractions.

This code appears in executable workflow guidance directly referenced by SKILL.md. An agent following that workflow may therefore reproduce the vulnerable implementation.

Exploitation requires an attacker to influence the value returned in the r_frame_rate field. This may be possible through malformed or unexpectedly parsed media metadata, manipulated probe output, or execution of an attacker-controlled program in place of the expected FFprobe binary. The latter condition separately requires control of executable resolution or configuration. If a malicious Python expression reaches this field, it is evaluated in the process context.

The workflow also fails to use `c ...[truncated 1462 chars]

Remediation
View remediation

Remediation Suggestions

Replace eval() with strict rational-number parsing:

python
from fractions import Fraction

raw_frame_rate = video_stream["r_frame_rate"]

try:
    fps = float(Fraction(raw_frame_rate))
except (ValueError, ZeroDivisionError):
    raise ValueError(f"Invalid frame rate: {raw_frame_rate!r}")

Apply the following additional controls:

  1. Run FFprobe with check=True and an execution timeout.
  2. Validate that r_frame_rate matches an expected numeric rational format, such as ^\d+/\d+$, before parsing it.
  3. Reject zero denominators and enforce a reasonable frame-rate range.
  4. Catch subprocess.CalledProcessError, JSON parsing errors, and missing-stream errors explicitly.
  5. Resolve FFprobe through a trusted absolute path or verify the selected executable to reduce executable-search-path substitution risk.
  6. Remove all recommendations to use eval() from reference documentation and examples.

A hardened implementation could use:

python
import json
import re
import subprocess
from fractions import Fraction

def analyze_video(input_file):
    cmd = [
        "/trusted/path/to/ffprobe",
        "-v", "error",
        "-print_format", "json",
        "-show_format",
        "-show_streams",
        input_file,
    ]

    result = subprocess.run(
        cmd,
        capture_output=True,
        text=True,
        check=True,
        timeout=30,
    )
    metadata = json.loads(result.stdout)
    video_stream = next(
        stream for stream in metadata["streams"]
        if stream.get("codec_type") == "video"
    )

    raw_frame_rate = video_stream["r_frame_rate"]
    if not re.fullmatch(r"\d+/\d+", raw_frame_rate):
        raise ValueError("Invalid frame-rate representation")

    fps = float(Fraction(raw_frame_rate))
    if not 0 < fps <= 1000:
        raise ValueError("Frame rate is outside the permitted range")

T09 · Insecure Skill Coding Practices

Note
Location
scripts/encoders/two_pass_encoder.py:151
Finding

Predictable Shared Temporary Files Used for Two-Pass Encoding

Content
View full analysis

Vulnerability Details

File Location: scripts/encoders/two_pass_encoder.py:151-176, 474-487; duplicate construction at scripts/builders/ffmpeg_builder.py:123-130
Vulnerability Type: Predictable temporary-file path and cross-job file collision
Risk Level: Low

Vulnerable Code

The encoder uses a fixed pass-log prefix in the system-wide temporary directory:

python
# First pass: analysis without an output file
pass1_params = base_params.copy()
pass1_params.extend(["-pass", "1", "-an", "-f", "null"])

# Windows and Unix use different null devices
if os.name == "nt":
    pass1_params.append("NUL")
else:
    pass1_params.append("/dev/null")

pass1_cmd = " ".join(pass1_params)

# Second pass: actual encoding
pass2_params = base_params.copy()
pass2_params.extend(
    [
        "-pass",
        "2",
        "-passlogfile",
        os.path.join(self.temp_dir, "ffmpeg2pass"),
        "-c:a",
        audio_codec,
        "-b:a",
        audio_bitrate,
        output_file,
    ]
)

pass2_cmd = " ".join(pass2_params)

Cleanup targets the same globally predictable filenames:

python
def _cleanup_temp_files(self):
    """Clean up temporary two-pass encoding files."""
    temp_files = [
        os.path.join(self.temp_dir, "ffmpeg2pass-0.log"),
        os.path.join(self.temp_dir, "ffmpeg2pass-0.log.mbtree"),
    ]

    for file in temp_files:
        if os.path.exists(file):
            try:
                os.remove(file)
            except:
                pass

The command builder repeats the same pattern:

python
if command.two_pass:
    cmd_parts.extend(["-pass", str(command.pass_number)])
    if command.pass_number == 2:
        # Add passlogfile for the second pass
        import tempfile

        cmd_parts.extend(["-passlogfile", tempfile.gettempdir() + "/ffmpeg2pass"])

Technical Analysis

All two-pass encoding jobs use the fixed prefix ffmpeg2pass under the shared system temporary directory. FFmpeg commonly derives fi ...[truncated 2508 chars]

Remediation
View remediation

Remediation Suggestions

Use a private, randomized directory and pass-log prefix for each encoding operation:

python
import tempfile
from pathlib import Path

with tempfile.TemporaryDirectory(prefix="ffmpeg-master-") as temp_dir:
    passlog_prefix = str(Path(temp_dir) / "passlog")

    pass1_params.extend([
        "-pass", "1",
        "-passlogfile", passlog_prefix,
        "-an", "-f", "null",
        "/dev/null",
    ])

    pass2_params.extend([
        "-pass", "2",
        "-passlogfile", passlog_prefix,
        "-c:a", audio_codec,
        "-b:a", audio_bitrate,
        output_file,
    ])

    # Execute both passes before leaving the context.

Apply these hardening measures:

  1. Generate a separate temporary directory for every encoding job.
  2. Ensure the temporary directory is created with owner-only permissions.
  3. Pass the same randomized -passlogfile prefix explicitly to both encoding passes.
  4. Keep the private directory alive until both passes finish.
  5. Let TemporaryDirectory remove the isolated directory instead of deleting predictable global filenames.
  6. Avoid broad exception suppression during cleanup; record failures without exposing sensitive paths.
  7. Apply the same correction to scripts/builders/ffmpeg_builder.py.
  8. Add concurrent-encoding tests to verify that pass logs never collide.
  9. On platforms supporting it, inspect unexpected pre-existing files and reject symbolic links or non-regular files before use.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (111)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documentation states it may automatically probe local hardware using tools like nvidia-smi, vainfo, and similar utilities, yet these host-inspection behaviors are not explicitly described in the top-level purpose or constrained by permissions. Undeclared environment probing expands data collection and system fingerprinting beyond straightforward media processing, which can surprise users and increase privacy and attack-surface concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill documentation states it may automatically probe local hardware using tools like nvidia-smi, vainfo, and similar utilities, yet these host-inspection behaviors are not explicitly described in the top-level purpose or constrained by permissions. Undeclared environment probing expands data collection and system fingerprinting beyond straightforward media processing, which can surprise users and increase privacy and attack-surface concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documentation states it may automatically probe local hardware using tools like nvidia-smi, vainfo, and similar utilities, yet these host-inspection behaviors are not explicitly described in the top-level purpose or constrained by permissions. Undeclared environment probing expands data collection and system fingerprinting beyond straightforward media processing, which can surprise users and increase privacy and attack-surface concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill documentation states it may automatically probe local hardware using tools like nvidia-smi, vainfo, and similar utilities, yet these host-inspection behaviors are not explicitly described in the top-level purpose or constrained by permissions. Undeclared environment probing expands data collection and system fingerprinting beyond straightforward media processing, which can surprise users and increase privacy and attack-surface concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documentation states it may automatically probe local hardware using tools like nvidia-smi, vainfo, and similar utilities, yet these host-inspection behaviors are not explicitly described in the top-level purpose or constrained by permissions. Undeclared environment probing expands data collection and system fingerprinting beyond straightforward media processing, which can surprise users and increase privacy and attack-surface concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill documentation states it may automatically probe local hardware using tools like nvidia-smi, vainfo, and similar utilities, yet these host-inspection behaviors are not explicitly described in the top-level purpose or constrained by permissions. Undeclared environment probing expands data collection and system fingerprinting beyond straightforward media processing, which can surprise users and increase privacy and attack-surface concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill documentation states it may automatically probe local hardware using tools like nvidia-smi, vainfo, and similar utilities, yet these host-inspection behaviors are not explicitly described in the top-level purpose or constrained by permissions. Undeclared environment probing expands data collection and system fingerprinting beyond straightforward media processing, which can surprise users and increase privacy and attack-surface concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documentation states it may automatically probe local hardware using tools like nvidia-smi, vainfo, and similar utilities, yet these host-inspection behaviors are not explicitly described in the top-level purpose or constrained by permissions. Undeclared environment probing expands data collection and system fingerprinting beyond straightforward media processing, which can surprise users and increase privacy and attack-surface concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documentation states it may automatically probe local hardware using tools like nvidia-smi, vainfo, and similar utilities, yet these host-inspection behaviors are not explicitly described in the top-level purpose or constrained by permissions. Undeclared environment probing expands data collection and system fingerprinting beyond straightforward media processing, which can surprise users and increase privacy and attack-surface concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documentation states it may automatically probe local hardware using tools like nvidia-smi, vainfo, and similar utilities, yet these host-inspection behaviors are not explicitly described in the top-level purpose or constrained by permissions. Undeclared environment probing expands data collection and system fingerprinting beyond straightforward media processing, which can surprise users and increase privacy and attack-surface concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill documentation states it may automatically probe local hardware using tools like nvidia-smi, vainfo, and similar utilities, yet these host-inspection behaviors are not explicitly described in the top-level purpose or constrained by permissions. Undeclared environment probing expands data collection and system fingerprinting beyond straightforward media processing, which can surprise users and increase privacy and attack-surface concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill documentation states it may automatically probe local hardware using tools like nvidia-smi, vainfo, and similar utilities, yet these host-inspection behaviors are not explicitly described in the top-level purpose or constrained by permissions. Undeclared environment probing expands data collection and system fingerprinting beyond straightforward media processing, which can surprise users and increase privacy and attack-surface concerns.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares operational guidance that clearly implies shell execution, file reads, and file writes, but it does not declare any explicit tool scope such as allowed tools or permissions. This creates an overbroad execution surface where a host may grant more capability than intended, reducing reviewability and increasing the chance of unsafe command or filesystem use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation criteria are extremely broad, effectively matching almost any video-related request. In an agent environment with shell and filesystem capabilities, overbroad triggering increases the chance the skill is invoked unnecessarily and runs powerful media-processing or probing commands on user files without sufficiently precise intent matching.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file documents operations such as compress_to_target_size() that write output files, and elsewhere build_and_run() that executes commands, but it does not include any warning about overwriting outputs, altering user files, or invoking external processing. For markdown files, the skill description should disclose behaviors that can affect user data or system integrity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The batch workflow shows processing several input/output pairs and saving a batch report, which can create or modify multiple files, but the documentation does not warn users about the scope of those writes. In markdown documentation, bulk operations affecting user files should be explicitly disclosed.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The workflow trigger phrases are broad enough that ordinary conversation about videos could unintentionally activate this skill, causing it to recommend or prepare media-processing actions when the user did not clearly request them. In an agent setting, over-broad routing increases the chance of unintended file operations or generation of risky FFmpeg commands, especially because the same document also includes overwrite-prone examples and file-manipulating workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Many command examples include FFmpeg's '-y' flag, which overwrites existing output files without prompting. In a file-processing skill, this creates a realistic risk of silent data loss if output paths collide with existing files or are chosen automatically, and the broad trigger design makes accidental invocation more plausible.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

该 markdown 文件以中文标题和正文直接规定了技能文档的交互/说明语言,但没有提供多语言选项、用户选择机制,或说明这是特定地区/合规场景所必需。根据语言/区域政策,这类未获用户选择的固定语言约束属于自然语言层面的策略问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file is written entirely in Chinese, including the title and all instructional content, with no indication that language selection is optional or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy, a skill that effectively requires a specific language without opt-in or justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documentation forces a single language/locale experience throughout the file, and there is no opt-in, alternate language reference, or justification that this skill is intentionally region-specific. Under the stated policy, forcing a specific language without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/quickstart.md (reported line 29)May include surrounding context.

Linux (Ubuntu/Debian):

bash
sudo apt update
sudo apt install ffmpeg

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/quickstart.md (reported line 30)May include surrounding context.

Linux (Ubuntu/Debian):

bash
sudo apt update
sudo apt install ffmpeg

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/troubleshooting.md (reported line 50)May include surrounding context.

Linux (Ubuntu/Debian):

bash
sudo apt update
sudo apt install ffmpeg

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/troubleshooting.md (reported line 51)May include surrounding context.

Linux (Ubuntu/Debian):

bash
sudo apt update
sudo apt install ffmpeg

Static analysis

No suspicious patterns detected.