Back to skill

Security audit

Popcorn CLI

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed CLI wrapper for Popcorn media generation, with clear warnings about local API-key storage and sending prompts to Popcorn.

Install only if you trust the Popcorn CLI package and backend. Keep ~/.popcorn-cli/config.json private, avoid using sensitive prompts or customer data in task parameters, and prefer a controlled environment because the npm package version is not pinned in the skill metadata.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Unpinned Executable npm Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12–16
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code

yaml
install:
  - kind: node
    package: "@baomihuatop/popcorn-cli"
    bins:
      - popcorn-cli

Technical Analysis

The Skill installs an executable third-party npm package without specifying an exact version, lockfile, or integrity hash. Consequently, the code installed during a future deployment can differ from the package version assessed when this Skill was reviewed.

Because the dependency provides the popcorn-cli executable, its code runs under the identity and permissions of the Agent user. Package installation may also execute npm lifecycle scripts, depending on the installer configuration. The dependency implementation is not included in this repository, so its runtime behavior, transitive dependencies, and handling of API credentials cannot be independently verified from the audited files.

This is a supply-chain weakness rather than evidence that the currently published package is malicious.

Attack Path

  1. An attacker compromises the npm publisher account, package release process, or a transitive dependency.
  2. The attacker publishes a malicious release under the existing package name.
  3. A subsequent Skill installation resolves the unpinned package to the malicious release.
  4. Malicious code executes during installation or when popcorn-cli is invoked.
  5. The code accesses data available to the Agent process, potentially including the Popcorn API key, submitted prompts, generated media, task identifiers, and other user-readable files.

Impact Assessment

Exploitation could result in arbitrary code execution with the privileges of the user installing or invoking the Skill. The practical scope includes files, environment variables, network credentials, and services accessible to that account. The finding does not ind ...[truncated 157 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin @baomihuatop/popcorn-cli to an exact, reviewed version rather than resolving an unspecified release.
  2. Provide a lockfile and verify the package with a trusted registry integrity hash.
  3. Disable npm lifecycle scripts during installation unless they are explicitly required and audited.
  4. Audit the package and all transitive dependencies with software-composition analysis and malware scanning.
  5. Publish verifiable source code corresponding to each distributed package release.
  6. Run the CLI with least privilege in a sandbox that restricts filesystem, environment-variable, and network access.
  7. Establish a controlled update process that reviews and approves new versions before deployment.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:65
Finding

API Key Stored in a Plaintext Local Configuration File

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 65–75
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: Medium

Vulnerable Configuration

text
~/.popcorn-cli/config.json

apiKey

The documentation identifies this file as the persistent configuration location and explicitly states that it stores the API key as a plaintext secret.

Technical Analysis

Persisting an API key in an ordinary JSON file exposes the credential to any process or user capable of reading that file. Documentation warnings can reduce accidental disclosure, but they do not enforce restrictive permissions, encryption at rest, output redaction, or integration with a protected credential store.

The risk is greater on shared workstations, CI runners, Agent environments, or systems where home directories are collected by backup, telemetry, support, or log-processing tools. The audited documentation does not establish that the CLI creates the file with owner-only permissions.

The repository does not contain a hardcoded API key, and it expressly warns users not to disclose the credential. The issue is the documented plaintext storage design.

Attack Path

  1. A user configures the CLI with a valid Popcorn API key.
  2. The CLI writes the credential to ~/.popcorn-cli/config.json.
  3. A local process, another user on a misconfigured shared system, a compromised Agent dependency, or a backup/log collection mechanism reads or copies the file.
  4. The attacker extracts the apiKey value.
  5. The attacker authenticates to the Popcorn backend as the affected user or tenant and performs operations permitted by that key.

Impact Assessment

A stolen key may permit unauthorized model queries, task submissions, task-status queries, consumption of account resources, and access to task metadata or generated result URLs, subject to the backend permissions assigned to the key. The compromise is limited to the ...[truncated 103 chars]

Remediation
View remediation

Remediation Suggestions

  1. Store API keys in an operating-system credential manager or an approved secret-management service instead of a plaintext JSON file.
  2. For environments without a credential manager, create the configuration directory with mode 0700 and the credential file with mode 0600; reject operation if ownership or permissions are unsafe.
  3. Support CI secret injection through a protected environment variable, secret-mounted file, or standard input without persisting the value.
  4. Ensure config show, errors, diagnostics, and telemetry always redact the complete API key.
  5. Exclude the configuration path from repositories, backups, support bundles, screenshots, and log collection.
  6. Use narrowly scoped, short-lived, and independently revocable credentials where supported.
  7. Document a credential-rotation procedure and revoke the key immediately after suspected exposure.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description and the main skill documentation are written entirely in Chinese, and the file does not indicate that language is optional or that users may choose another locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The user-facing description and default prompt are written only in Chinese, which can constitute a language/locale policy issue when no opt-in, alternative language, or regional scope is documented. The file does not indicate that this skill is intended only for Chinese-speaking users or that language selection is configurable.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.