Back to skill

Security audit

After Effects MCP

Security checks for vulnerabilities and agentic risk

Overview

This After Effects automation skill is mostly purpose-aligned, but its batch render script can write render outputs outside the intended folder when composition names are unsafe.

Review this skill before installing or using it. Only run the batch render script on trusted projects, avoid composition names containing path separators or '..', choose output folders carefully, and inspect the render queue output paths before starting a render. The issue is fixable by sanitizing composition names and confirming final output destinations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/batch_render.jsx:8
Finding

Path Traversal Through Unsanitized Composition Names

Content
View full analysis
Remediation
View remediation
|\x00-\x1F]/g, "_"); safe = safe.replace(/\.\./g, "_"); if (safe === "" || safe === "." || safe === "..") { throw new Error("Invalid composition name for output"); } return safe; } var safeName = safeOutputName(compName); var outputDirectory = new Folder(outputPath); var destination = new File(outputDirectory.fsName + "/" + safeName + ".mov"); output.file = destination; ``` Because simple replacement alone may not cover every platform-specific path behavior, the implementation should additionally compare canonical paths and enforce that the final destination is contained within the approved output directory. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file includes examples for importing files, saving a project, and closing a project, but it does not warn users that these actions can modify project state or affect unsaved work. Under the markdown-specific missing-warning criterion, descriptions that cover potentially user-impacting operations should disclose those effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The Render Queue example sets an output file path and invokes rendering, which results in file creation on disk, but the markdown does not mention this behavior or its impact. For markdown skill documentation, file-affecting behavior should be disclosed when it may affect user data or system state.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.