Back to skill

Security audit

Veo

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Google Veo video generator with disclosed API-key use and output-file writing, with only a minor dependency-pinning caution.

Install only if you are comfortable providing a Gemini API key and sending your video prompts and any selected reference images to Google. For tighter supply-chain control, pin or lock the google-genai dependency before running in a sensitive environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/generate_video.py:2
Finding

Unbounded Runtime Dependency Resolution

Content
View full analysis

Vulnerability Details

File Location: scripts/generate_video.py, lines 2–7
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Complete Code Snippet:

python
# /// script
# requires-python = ">=3.10"
# dependencies = [
#     "google-genai>=1.0.0",
# ]
# ///

Technical Analysis

The script declares google-genai using the open-ended constraint >=1.0.0. The documented uv run workflow may resolve and install the dependency dynamically, but the project provides no exact version pin, upper bound, lockfile, or integrity hash.

Consequently, a future release satisfying this constraint can be loaded without having been reviewed with the Skill. Imported dependency code executes within the Skill's process and inherits access to its environment and filesystem. This includes access to GEMINI_API_KEY, user-selected reference images, generated video files, and other resources available under the invoking user's permissions.

This finding concerns uncontrolled dependency resolution. The audited code does not establish that the current google-genai package is malicious.

Attack Path

  1. An attacker compromises the upstream package, its publishing account, or a future compatible release.
  2. The attacker publishes a malicious version satisfying google-genai>=1.0.0.
  3. A user invokes the documented uv run command in an environment where that version is selected.
  4. uv retrieves and installs the newly resolved version.
  5. The script imports google.genai, causing package-controlled code to execute with the invoking user's privileges.
  6. The compromised dependency can read inherited environment variables, access files available to the process, modify output, or communicate with external systems.

Impact Assessment

Successful exploitation would provide code execution at the privilege level of the user running the Skill. The reachable scope includes the Skill proc ...[truncated 329 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin google-genai to an exact, reviewed version rather than using an open-ended lower bound.
  2. Commit a lockfile generated by uv and run the Skill with locked or frozen dependency resolution.
  3. Where supported, verify downloaded artifacts using cryptographic hashes.
  4. Configure package installation to use an explicitly trusted package index and disallow unexpected alternate sources.
  5. Update dependencies through a controlled process that includes security review, automated vulnerability scanning, and testing.
  6. Run the Skill with least privilege and provide only the environment variables and filesystem access required for video generation.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.