Back to skill

Security audit

Fact Checker

Security checks for vulnerabilities and agentic risk

Overview

This fact-checking skill is mostly purpose-aligned, but it includes under-controlled credential handling, external media upload, and shell-based media processing risks that users should review before installing.

Install only if you are comfortable with web/API-based fact checking and local media processing. Avoid using it on confidential claims, private videos, or sensitive images unless you disable optional external API paths or get explicit consent before uploads; API key checks should be fixed so keys are never printed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
references/video_pipeline.md:58
Finding

Unsafe Shell Interpolation of Untrusted Media File Paths

Content
View full analysis
" -vf "select=eq(pict_type\,I),scale=1280:-1" -vsync vfr -frame_pts 1 /tmp/factcheck_frames/frame_%04d.jpg -y 2>/dev/null ``` ```bash ffmpeg -i "" -vf "fps=1/10,scale=1280:-1" /tmp/factcheck_frames/frame_%04d.jpg -y 2>/dev/null ``` ```bash ffprobe -v quiet -print_format json -show_format -show_streams "" 2>/dev/null ``` The same pattern appears in the image pipeline: ```bash exiftool -json "" ``` ```bash c2patool "" ``` ### Technical Analysis `` represents a path influenced by an attached file or downloaded media. The instructions direct the Agent to substitute this value into shell command strings but do not require canonicalization, strict validation, argument-array execution, or reliable shell escaping. Wrapping a substituted value in double quotes is not sufficient if the Agent performs direct textual replacement. A filename containing a double quote followed by shell syntax can terminate the quoted argument and introduce additional commands. Filenames beginning with option characters may also be interpreted as command-line options by utilities that are not given an option terminator. The vulnerability depends on the execution layer implementing these examples through shell-string interpolation. The Skill does not provide safeguards that would prevent such an implementation. ### Attack Path 1. An attacker supplies an image or video with a crafted local filename containing quote characters and shell metacharacters. 2. The Skill routes the file to the image or video analysis pipeline. 3. Th ...[truncated 972 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/video_pipeline.md:58
Finding

Predictable Shared Temporary Paths Permit Symlink and Cross-Session Attacks

Content
View full analysis
" -vf "select=eq(pict_type\,I),scale=1280:-1" -vsync vfr -frame_pts 1 /tmp/factcheck_frames/frame_%04d.jpg -y 2>/dev/null ``` ```bash ffmpeg -i "" -vf "fps=1/10,scale=1280:-1" /tmp/factcheck_frames/frame_%04d.jpg -y 2>/dev/null ``` ```bash ffmpeg -i "" -vn -acodec pcm_s16le -ar 16000 /tmp/factcheck_audio.wav -y 2>/dev/null ``` ```bash which whisper 2>/dev/null && whisper /tmp/factcheck_audio.wav --model base --output_format txt --output_dir /tmp/ 2>/dev/null ``` ```bash rm -rf /tmp/factcheck_frames /tmp/factcheck_audio.wav /tmp/factcheck_audio.txt 2>/dev/null ``` ### Technical Analysis The workflow uses globally predictable paths under `/tmp` for extracted frames, audio, and transcripts. These paths are shared across every invocation and potentially across different users and processes. The commands do not create a private temporary directory atomically, verify ownership, reject symbolic links, or use exclusive file creation. The `-y` option directs `ffmpeg` to overwrite existing output files. A local adversary may therefore pre-create expected paths or symbolic links before processing begins. Concurrent fact-check operations can also read, overwrite, or delete one another's artifacts. The final broad cleanup command removes the fixed paths regardless of which invocation created them. ### Attack Path 1. A local attacker predicts `/tmp/factcheck_frames`, `/tmp/factcheck_audio.wav`, or `/tmp/factcheck_audio.txt`. 2. The attacker pre-creates one of these paths, creates malicious symbolic links, or waits for another user's processing artifacts. 3. A victim initiates video verification. 4. `ffmp ...[truncated 890 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/text_pipeline.md:11
Finding

API Keys Are Printed and Exposed in Process Command Arguments

Content
View full analysis
" \ -d "languageCode=" \ -d "pageSize=10" \ -d "key=$GOOGLE_FACTCHECK_API_KEY" ``` The video pipeline repeats the unsafe presence check: ```bash echo "${OPENAI_API_KEY:-}" ``` It then places the OpenAI credential in a command argument: ```bash curl -s https://api.openai.com/v1/audio/transcriptions \ -H "Authorization: Bearer $OPENAI_API_KEY" \ -F file="@/tmp/factcheck_audio.wav" \ -F model="whisper-1" ``` ### Technical Analysis The Skill prints complete API-key values merely to determine whether the environment variables are set. Tool output may be retained in Agent context, command logs, execution telemetry, debugging output, or conversation records. The Google API key is supplied as a request parameter, which can expose it through process listings and URL logging. The OpenAI authorization header also appears in the `curl` process command line and may be visible to local process observers while the request is running. The endpoints are official Google and OpenAI services, and no attacker-controlled exfiltration endpoint was identified. The vulnerability is the unnecessary disclosure and insecure handling of secrets rather than evidence of deliberate credential theft. ### Attack Path 1. The user initiates text or video verification while the relevant API key exists in the environment. 2. The pipeline runs `echo` and emits the complete key into tool output. 3. The output is retained in logs, telemetry, Agent context, or conversation history. 4. Alternatively, a loca ...[truncated 722 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/video_pipeline.md:97
Finding

User Video Audio May Be Uploaded to OpenAI Without Transaction-Specific Consent

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (21)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The pipeline explicitly reads OPENAI_API_KEY from the local environment and uses it to make an outbound transcription request, which crosses a clear trust boundary. Accessing local secrets and transmitting user-derived audio to an external API is sensitive behavior not clearly constrained by the skill description and could expose credentials, private media, or both.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/video_pipeline.md (reported line 120)May include surrounding context.

2e. Cleanup

bash
rm -rf /tmp/factcheck_frames /tmp/factcheck_audio.wav /tmp/factcheck_audio.txt 2>/dev/null

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/video_pipeline.md (reported line 120)May include surrounding context.

2e. Cleanup

bash
rm -rf /tmp/factcheck_frames /tmp/factcheck_audio.wav /tmp/factcheck_audio.txt 2>/dev/null

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/video_pipeline.md (reported line 120)May include surrounding context.

2e. Cleanup

bash
rm -rf /tmp/factcheck_frames /tmp/factcheck_audio.wav /tmp/factcheck_audio.txt 2>/dev/null

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The activation examples include very broad phrases such as asking "is this true?" about any statement and asking to verify content in any language. These conditions lack negative examples or tighter scope boundaries, which could cause the skill to activate for ordinary conversational skepticism rather than clear fact-checking tasks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill directs the agent to fetch arbitrary URLs and download linked media without an upfront warning or confirmation. That can cause unintended network access to attacker-controlled hosts, expose environment-specific metadata such as IP/user agent, and retrieve untrusted content without the user's informed consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to append a preference to AGENTS.md after a successful run, which is a persistent workspace modification unrelated to the immediate fact-check task. This creates durable behavior changes from natural-language interaction and can surprise users or alter future agent routing beyond the current session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The AGENTS.md modification instruction lacks a clear warning that it will make a persistent change to the workspace. Users may consent to a convenience feature without understanding that it alters future agent behavior outside the current interaction.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Persisting user preferences by writing natural-language directives into AGENTS.md creates a pathway for long-lived instruction injection. Even if the current text is harmless, this pattern normalizes storing user-supplied behavioral directives in a file that may influence later sessions and tasks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The pipeline explicitly instructs extraction and analysis of EXIF data, including GPS coordinates and device details, without requiring user consent, minimization, or a privacy warning. In a fact-checking skill, this can expose sensitive location or device information from user-supplied local images that may be unnecessary for the verification task.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/image_pipeline.md (reported line 54)May include surrounding context.

md
- **GPS coordinates**: if present, do they match the claimed location?
- **AI generation markers**: some AI tools embed identifiers in metadata

**If not available**, skip silently. Do not ask the user to install it.

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly sends the first 200 characters of user-provided text to Google's Fact Check API without any user-facing notice, consent, or data-minimization guidance. Because fact-check requests may contain sensitive personal, confidential, or unpublished material, this creates a real privacy and data-disclosure risk through third-party transmission.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This command performs direct external transmission of user-derived input to a third-party API. In the context of a fact-checking skill, user submissions can include sensitive allegations, private messages, or identifying details, so sending even a truncated excerpt externally without clear consent or sanitization is a meaningful privacy vulnerability.

Content

Scanner excerpt · references/text_pipeline.md (reported line 18)May include surrounding context.

  1. If the key is set (non-empty), query the API:
    bash
    curl -s -G "https://factchecktools.googleapis.com/v1alpha1/claims:search" \
      --data-urlencode "query=<FIRST 200 CHARACTERS OF INPUT TEXT>" \
      -d "languageCode=<LANGUAGE>" \
      -d "pageSize=10" \
    

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The mandated English cross-check forces user content or its translated keywords into a second-language search workflow regardless of user preference or consent. While primarily a privacy and autonomy issue rather than a classic exploit, it increases unnecessary external exposure of user-derived content and can violate expectations for language-restricted handling.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to probe the local environment for ffmpeg and provides package-manager installation commands, expanding behavior from content analysis into system inspection and operational guidance. In an agent context, this can normalize shell access and encourage privileged changes on the host that are not strictly necessary for the skill's primary fact-checking function.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
90% confidence
Finding

The skill recommends sudo apt install ffmpeg, which encourages privileged execution on the host system. Even as guidance rather than direct execution, embedding root-level package installation in a content-processing workflow increases the chance of unnecessary system modification and weakens least-privilege expectations.

Content

Scanner excerpt · references/video_pipeline.md (reported line 50)May include surrounding context.

md
**If ffmpeg is NOT available**, recommend installation:
> ⚠️ **For deeper video analysis, install ffmpeg** (one command, ~30 seconds):
> - **Ubuntu/Debian**: `sudo apt install ffmpeg`
> - **macOS**: `brew install ffmpeg`
> - **Windows**: `winget install ffmpeg`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill directs extracted audio to be uploaded to an external transcription service without an in-flow warning or consent checkpoint. Audio often contains sensitive personal or confidential information, so silent transmission creates a privacy and compliance risk even if the service itself is legitimate.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

This instruction performs a direct outbound request to api.openai.com carrying extracted audio and an authorization header. External transmission of potentially sensitive media content is a genuine risk when done from a skill without explicit consent, data-minimization controls, or a trusted mediation layer.

Content

Scanner excerpt · references/video_pipeline.md (reported line 103)May include surrounding context.

text
   If set:
   ```bash
   curl -s https://api.openai.com/v1/audio/transcriptions \
     -H "Authorization: Bearer $OPENAI_API_KEY" \
     -F file="@/tmp/factcheck_audio.wav" \
     -F model="whisper-1"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This instruction requires a Chinese-only template with no mixing of English whenever the user uses Chinese. That is a language policy constraint expressed in natural language, and the file does not offer the user a choice or opt-in for output language or mixed-language formatting.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill contemplates inspecting local files and storing file path/source metadata internally without warning the user. While this may be operationally useful, it increases privacy risk by handling local artifacts and metadata that could reveal sensitive file names, locations, or provenance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction says the report 'must' use the Chinese template and forbids mixing English when the user uses Chinese. This is a natural-language locale policy constraint, and the file does not offer the user any option to choose a different reporting language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.