Back to skill

Security audit

Byteplus Mediakit Video Highlights

Security checks across malware telemetry and agentic risk

Overview

This skill is a focused BytePlus MediaKit helper that submits or queries football highlight jobs using disclosed credentials and API calls.

Install only if you intend to let the agent submit/query BytePlus MediaKit highlight jobs using your MediaKit credentials. Configure API keys outside chat, avoid untrusted endpoint/header overrides, and remember submitted video URLs, prompts, callback data, and task queries are sent to the configured MediaKit endpoint.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill clearly instructs the agent to use environment variables, read local configuration files such as ~/.mediakit/config.json, and make outbound network requests, yet the metadata does not declare corresponding permissions. That mismatch can bypass user/admin expectations about what the skill can access and increases the risk of unintended secret access or external data transmission.

Vague Triggers

Low
Confidence
80% confidence
Finding
The trigger evals only cover a few football-highlight creation and task-status queries, leaving the activation boundary for adjacent video-editing requests insufficiently specified. This can cause the skill to trigger too broadly on unrelated editing tasks or fail to gate unsupported requests, increasing the chance of unintended tool use or user confusion.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.