T09 · Insecure Skill Coding Practices
- Location
references/detailed_workflows.md:40- Finding
Unsafe Evaluation of FFprobe Frame-Rate Metadata
- Content
View full analysis
Vulnerability Details
File Location:
references/detailed_workflows.md:40-65
Vulnerability Type: Arbitrary Python expression evaluation
Risk Level: MediumVulnerable Code
python import subprocess import json def analyze_video(input_file): cmd = [ 'ffprobe', '-v', 'quiet', '-print_format', 'json', '-show_format', '-show_streams', input_file ] result = subprocess.run(cmd, capture_output=True, text=True) metadata = json.loads(result.stdout) # Extract key information video_stream = next(s for s in metadata['streams'] if s['codec_type'] == 'video') audio_stream = next(s for s in metadata['streams'] if s['codec_type'] == 'audio') return { 'format': metadata['format']['format_name'], 'codec': video_stream['codec_name'], 'width': int(video_stream['width']), 'height': int(video_stream['height']), 'fps': eval(video_stream['r_frame_rate']),Technical Analysis
The primary documented video-analysis workflow evaluates the
r_frame_ratevalue returned by FFprobe using Python'seval(). A normal value is a rational expression such as30000/1001, buteval()accepts arbitrary Python expressions rather than limiting the input to numeric fractions.This code appears in executable workflow guidance directly referenced by
SKILL.md. An agent following that workflow may therefore reproduce the vulnerable implementation.Exploitation requires an attacker to influence the value returned in the
r_frame_ratefield. This may be possible through malformed or unexpectedly parsed media metadata, manipulated probe output, or execution of an attacker-controlled program in place of the expected FFprobe binary. The latter condition separately requires control of executable resolution or configuration. If a malicious Python expression reaches this field, it is evaluated in the process context.The workflow also fails to use `c ...[truncated 1462 chars]
- Remediation
View remediation
Remediation Suggestions
Replace
eval()with strict rational-number parsing:python from fractions import Fraction raw_frame_rate = video_stream["r_frame_rate"] try: fps = float(Fraction(raw_frame_rate)) except (ValueError, ZeroDivisionError): raise ValueError(f"Invalid frame rate: {raw_frame_rate!r}")Apply the following additional controls:
- Run FFprobe with
check=Trueand an execution timeout. - Validate that
r_frame_ratematches an expected numeric rational format, such as^\d+/\d+$, before parsing it. - Reject zero denominators and enforce a reasonable frame-rate range.
- Catch
subprocess.CalledProcessError, JSON parsing errors, and missing-stream errors explicitly. - Resolve FFprobe through a trusted absolute path or verify the selected executable to reduce executable-search-path substitution risk.
- Remove all recommendations to use
eval()from reference documentation and examples.
A hardened implementation could use:
python import json import re import subprocess from fractions import Fraction def analyze_video(input_file): cmd = [ "/trusted/path/to/ffprobe", "-v", "error", "-print_format", "json", "-show_format", "-show_streams", input_file, ] result = subprocess.run( cmd, capture_output=True, text=True, check=True, timeout=30, ) metadata = json.loads(result.stdout) video_stream = next( stream for stream in metadata["streams"] if stream.get("codec_type") == "video" ) raw_frame_rate = video_stream["r_frame_rate"] if not re.fullmatch(r"\d+/\d+", raw_frame_rate): raise ValueError("Invalid frame-rate representation") fps = float(Fraction(raw_frame_rate)) if not 0 < fps <= 1000: raise ValueError("Frame rate is outside the permitted range")- Run FFprobe with
