Back to skill

Security audit

Personal Video Dl

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent video downloader, but it needs Review because it can automatically install or upgrade an unpinned external dependency on the user's machine.

Review before installing. This skill is not clearly malicious, but users should understand that it will contact external video services, write downloaded files locally, and may change the Python environment by installing or upgrading yt-dlp. Safer use would require preinstalling a reviewed, pinned yt-dlp version and disabling automatic pip installation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
video_downloader.py:29
Finding

Automatic Installation of an Unpinned Third-Party Dependency

Content
View full analysis

Vulnerability Details

File Location: video_downloader.py:29-30
Vulnerability Type: Unpinned dependency installation from a mutable package source
Risk Level: Medium

Vulnerable Code

python
subprocess.run([sys.executable, '-m', 'pip', 'install', '-U', 'yt-dlp'], 
              check=True, capture_output=True)

The installation is triggered automatically during ordinary download operations when the yt-dlp executable cannot be found:

python
# 检查 yt-dlp
if not check_yt_dlp():
    print("⚠️  yt-dlp 未安装")
    if not install_yt_dlp():
        return False

Technical Analysis

The script invokes pip with install -U yt-dlp without specifying an exact version or verifying an expected package hash. As a result, the package artifact installed at runtime may change independently of the audited project. pip also honors environment-level package index configuration, so the package may be resolved through a configured index rather than a fixed, explicitly trusted repository.

This creates a supply-chain risk: compromise of the package distribution channel, a configured package index, or a future upstream release could cause attacker-controlled code to be installed. Python packages can execute build or installation logic, and the installed yt-dlp program is subsequently executed by the script.

The use of an argument-list subprocess call prevents shell metacharacters from producing command injection, but it does not mitigate dependency provenance or integrity risks.

Attack Path

  1. An attacker compromises a package source used by pip, controls a configured package index, or causes a malicious future package artifact to be served.
  2. A user runs a normal video download while the yt-dlp executable is unavailable.
  3. download_video() automatically calls install_yt_dlp().
  4. The script runs python -m pip install -U yt-dlp without a pinned version or package hash.
  5. pip do ...[truncated 672 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove automatic package installation from the normal download path. If the dependency is missing, stop and provide explicit setup instructions.
  2. Pin yt-dlp to a reviewed exact version rather than using an unconstrained upgrade:
    text
    yt-dlp==REVIEWED_VERSION
    
  3. Maintain a lock file containing cryptographic hashes and install with hash enforcement:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  4. Use a dedicated virtual environment with a trusted, explicitly configured package index.
  5. Separate installation from execution and require informed user confirmation before retrieving third-party software.
  6. Review and intentionally update the pinned dependency through a controlled maintenance process, including provenance and integrity checks.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (10)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises and invokes capabilities that imply shell execution, network access, and file reading, but it does not declare any explicit tool scope or permissions. This weakens security review and runtime containment because users and the platform cannot clearly verify what the skill is allowed to do before activation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation does not warn users that submitted URLs and associated request metadata will be sent to third-party video platforms during download. This creates a privacy and transparency issue, especially when links may contain personal identifiers, private playlist references, or tracking parameters.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include broad natural-language expressions like '帮我下载这个视频', which are common in ordinary conversation and can cause accidental or ambiguous activation. Unintended activation is risky here because the skill can initiate network requests, process attacker-provided URLs, and write files to disk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file's user-facing description and CLI help text are written in Chinese, which effectively forces a specific language for users. The policy allows locale constraints only when users are given a choice or the restriction is clearly justified, neither of which is present here.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · video_downloader.py (reported line 20)May include surrounding context.

python
def check_yt_dlp():
    """检查 yt-dlp 是否已安装"""
    try:
        result = subprocess.run(['yt-dlp', '--version'], 
                              capture_output=True, text=True, timeout=10)
        return result.returncode == 0
    except FileNotFoundError:

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Allowing the tool to install or upgrade software through pip exceeds the stated purpose and materially increases risk, because it changes the host environment and pulls executable code from external sources. In the context of an agent skill, this is more dangerous because the action may occur non-interactively and be overlooked by the user.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
93% confidence
Finding

The skill can automatically install or upgrade yt-dlp via pip at runtime, which introduces supply-chain and environment-modification risk beyond simple video downloading. If triggered in a sensitive environment, it may fetch and execute unpinned third-party code from package indexes without explicit administrative review.

Content

Scanner excerpt · video_downloader.py (reported line 33)May include surrounding context.

python
print("📦 正在安装 yt-dlp...")
    try:
        # 尝试使用 pip 安装
        subprocess.run([sys.executable, '-m', 'pip', 'install', '-U', 'yt-dlp'], 
                      check=True, capture_output=True)
        print("✅ yt-dlp 安装成功")
        return True

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · video_downloader.py (reported line 144)May include surrounding context.

python
# 执行下载
    print("\n⬇️  开始下载...\n")
    try:
        result = subprocess.run(cmd, capture_output=False, text=True)
        
        if result.returncode == 0:
            print("\n" + "=" * 60)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The argparse description, examples, and option help strings are all Chinese-language user interface text. This imposes a single language on all users without offering an alternative or documenting a justified regional scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

All user-facing instructions and metadata are presented in Chinese, and the file does not indicate that this language choice is optional or justified by a region-specific purpose. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.