Back to skill

Security audit

VidIQ - Video Intelligence

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent video utility, but its shell script has real input-validation and temporary-file safety issues that could expose files or run unintended commands.

Review before installing. This skill does normal video processing, but use it only with trusted arguments and non-sensitive media until it validates numeric inputs and moves downloads/generated media into a private, permission-restricted cache with clear cleanup behavior.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/vidiq.sh:91
Finding

Command Execution Through Unvalidated Bash Arithmetic Expressions

Content
View full analysis
/dev/null else INTERVAL=$(( DUR / (N - 1) )) for i in $(seq 1 "$N"); do TS=$(( (i - 1) * INTERVAL )) if (( TS > DUR )); then TS=$DUR; fi FNAME=$(printf "frame_%03d_%02dm%02ds.jpg" "$i" "$((TS/60))" "$((TS%60))") ffmpeg -y -ss "$TS" -i "$LOCAL" -frames:v 1 -q:v 2 "$OUTDIR/$FNAME" 2>/dev/null echo " [$i/$N] ${TS}s -> $FNAME" done fi ``` ```bash mosaic) COLS="${1:-4}" N="${2:-16}" OUT="$WORK/mosaic_$(date +%s).jpg" DUR=$(get_duration) echo "[vidiq] Creating ${COLS}x mosaic from $N frames..." TMPDIR="$WORK/.mosaic_tmp_$$" mkdir -p "$TMPDIR" INTERVAL=$(( DUR / N )) for i in $(seq 1 "$N"); do TS=$(( (i - 1) * INTERVAL + INTERVAL / 2 )) ffmpeg -y -ss "$TS" -i "$LOCAL" -frames:v 1 -q:v 3 -vf "scale=320:-1" "$TMPDIR/f$(printf '%03d' $i).jpg" 2>/dev/null done ffmpeg -y -pattern_type glob -i "$TMPDIR/f*.jpg" \ -vf "tile=${COLS}x$(( (N + COLS - 1) / COLS ))" -q:v 2 "$OUT" 2>/dev/null ``` ### Technical Analysis The `frames` and `mosaic` commands assign caller-controlled strings directly to `N` and `COLS`. Those values are subsequently referenced in Bash arithmetic contexts such as: ```bash (( N == 1 )) $(( DUR / (N - 1) )) $(( DUR / N )) $(( (N + COLS - 1) / COLS )) ``` Bash arithmetic evaluation does not merely convert an arbitrary string into an integer. Variable values ...[truncated 1811 chars]
Remediation
View remediation
&2 exit 2 fi if (( 10#$value > maximum )); then printf '[vidiq] ERROR: %s must not exceed %d\n' "$name" "$maximum" >&2 exit 2 fi } N="${1:-10}" validate_positive_integer "frame count" "$N" 1000 N=$((10#$N)) ``` For mosaics, validate both dimensions independently: ```bash COLS="${1:-4}" N="${2:-16}" validate_positive_integer "column count" "$COLS" 50 validate_positive_integer "frame count" "$N" 1000 COLS=$((10#$COLS)) N=$((10#$N)) ``` Additional hardening should include: - Rejecting zero before any division. - Setting practical limits for frame counts, columns, GIF durations, and other resource-sensitive parameters. - Validating timestamps and scene thresholds against strict accepted formats. - Avoiding the treatment of untrusted strings as arithmetic expressions. - Applying execution time, file-size, disk-space, and process limits around expensive `ffmpeg` operations. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/vidiq.sh:23
Finding

Predictable Shared Temporary Files Permit Media Disclosure, Substitution, and Symlink Attacks

Content
View full analysis
&1 | tail -5 LOCAL="$CACHED" echo "[vidiq] Downloaded: $CACHED" fi ``` ```bash OUTDIR="$WORK/frames_$(date +%s)" mkdir -p "$OUTDIR" ``` ```bash OUT="${2:-$WORK/frame_$(date +%s).jpg}" ``` ```bash OUT="${3:-$WORK/clip_$(date +%s).mp4}" ``` ```bash OUT="${1:-$WORK/audio_$(date +%s).mp3}" ``` ```bash OUT="${3:-$WORK/gif_$(date +%s).gif}" ``` ```bash OUT="$WORK/mosaic_$(date +%s).jpg" ``` ### Technical Analysis The script places downloads and generated media in a fixed, shared directory under `/tmp`. It does not set a restrictive `umask`, verify directory ownership or permissions, or securely create output files. Most generated names contain only the current timestamp in seconds. These names are predictable and may collide when operations occur during the same second. Cache names are derived from the first 12 hexadecimal characters of an unsalted MD5 digest of the source URL, so anyone who knows or guesses the URL can calculate the corresponding path. The script trusts a cache entry whenever `[[ -f "$CACHED" ]]` succeeds. It does not establish that the file was created by the current user, is not attacker-controlled, and contains the expected media. Additio ...[truncated 2388 chars]
Remediation
View remediation
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code substantially aligns with the described video utility purpose: it can download videos from URLs, analyze metadata, extract clips, create GIFs, and uses ffmpeg plus yt-dlp. However, there are notable description/behavior discrepancies. The script also supports local files, which is broader than 'from any URL.' It exposes audio extraction and scene/mosaic/frame operations not mentioned in the short description, though some of these may be considered adjacent analysis features. More importantly, the 'AI-powered' claim is not supported by the provided code; nearly all behavior is conventional media processing with ffmpeg/ffprobe, and the only AI-like feature mentioned ('transcript' via whisper) is not implemented in the actual case statement. Because the description overstates AI behavior and omits some concrete capabilities, this is a mismatch overall.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The usage banner advertises a transcript command, which aligns with the manifest's 'AI-powered video intelligence' claim, but the case statement never implements transcript and the unknown-command help omits it. In practice, the script supports metadata extraction and media transforms, not transcription or broader AI analysis as described.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The header comment says vidiq.sh <url_or_path> transcript will extract audio and transcribe it, but there is no transcript) branch in the command dispatch. The code therefore contradicts its own usage documentation and will reject that command as unknown.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The markdown describes the skill as downloading and manipulating videos, but it does not warn up front that using a URL causes local retrieval and storage of media. The only disclosure appears later in notes, which may be easy to miss despite the data-handling impact on disk usage and privacy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The commands create frames, clips, GIFs, audio, and mosaics, which affect local user storage and may persist sensitive video content. The later notes mention output paths, but the skill does not clearly present this as a user-facing warning about generated artifacts and temporary files.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/vidiq.sh:82