Back to skill

Security audit

shellbot-creative

Security checks for vulnerabilities and agentic risk

Overview

This creative-media skill is mostly coherent, but it has a real unsafe shell-generation path that can turn a crafted brief into local command execution.

Review generated shell plans before running them, especially if the brief came from another person or an untrusted source. Do not put secrets, unreleased campaign details, customer data, or private media into prompts unless you are comfortable sending them to the selected provider. Pin or avoid the npx create-video@latest command in controlled environments.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/run_full_dry_run.py:121
Finding

Shell Command Injection Through an Unescaped Creative Brief

Content
View full analysis
None: lines = [ "#!/usr/bin/env bash", "set -euo pipefail", "", "if [[ -z \"${FREEPIK_API_KEY:-}\" ]]; then", " echo \"FREEPIK_API_KEY is required for this Freepik-first run.\" >&2", " exit 1", "fi", "", "mkdir -p ./creative-output/{assets,scenes,audio,final,manifests}", "", ] for item in commands: lines.append(f"echo \"=== {item['step']} ({item['provider']}) ===\"") lines.append(item["command"]) lines.append("") path.write_text("\n".join(lines) + "\n", encoding="utf-8") os.chmod(path, 0o755) ``` ### Technical Analysis The `--brief` command-line value is supplied by the user and passed into `build_storyboard()`. That function incorporates the brief into each scene's `visual_prompt`. `freepik_command_templates()` then places `scene['visual_prompt']` directly inside a single-quoted shell argument. Neither JSON encoding nor shell quoting is a ...[truncated 1980 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:154
Finding

Unpinned Third-Party Package Download and Execution Through npx

Content
View full analysis
Remediation
View remediation
`. 2. Document the expected package publisher, registry, and package identity so users can verify that the correct dependency is being installed. 3. Use a committed lockfile for the generated or maintained Remotion project and enforce locked dependency installation. 4. Verify package integrity through the package manager's integrity metadata or an independently recorded checksum where practical. 5. Review the pinned package's direct and transitive dependencies before updating it. 6. Require explicit user approval before downloading or executing third-party packages. 7. Perform installation in a restricted environment with minimal credentials and filesystem permissions, especially in automated Agent workflows. 8. Establish a controlled update process in which package upgrades are reviewed, tested, and deliberately pinned before release. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (63)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The description presents a broad end-to-end creative production system capable of generating/editing visual assets, producing audio, and assembling final videos using multiple named external tools. The supplied code only performs pre-production planning: it takes a brief and outputs structured storyboard JSON with scene timing and text prompts. This is related to creative workflows, but it is materially narrower than the declared purpose and lacks the core production capabilities and external integrations explicitly claimed. Therefore the description does not accurately represent the actual behavior of this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a media-production system focused on image/video generation, editing, audio creation, and Remotion assembly. The supplied code chunk does none of those things. Instead, it is purely an installation script that determines a target skills directory, copies the skill files there, optionally deletes an existing destination when --force is used, and cleans up copied cache/build directories. This is a materially different primary purpose and includes filesystem modification capabilities not described in the declared purpose. While installer scripts can be supporting infrastructure, this chunk itself does not implement or reflect the advertised creative functionality, so the description does not accurately represent what the supplied code actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a media-generation and editing pipeline, but the actual code shown performs only packaging of the skill folder for distribution. It does not generate or edit visual assets, create audio, invoke Freepik/fal.ai/Gemini/Remotion workflows, or implement any creative production features. Packaging is a materially different primary purpose from the declared end-user creative capabilities, so this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
96% confidence
Finding

This skill contains an executable shell script that performs filesystem writes and network operations, but the analysis indicates the shell capability is not declared in permissions. That mismatch can cause users or hosting systems to underestimate what the skill can do, reducing meaningful consent and control over execution of external requests.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/install_skill.sh (reported line 51)May include surrounding context.

sh
fi

cp -R "$SKILL_DIR" "$DEST"
rm -rf "$DEST/scripts/__pycache__" "$DEST/dist"

echo "$DEST"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill routes prompts and potentially user-supplied creative assets to third-party providers, but it does not prominently warn users that their data may leave the local environment. In a creative-production context, assets may include proprietary marketing material, unreleased product visuals, or personal media, so lack of disclosure can lead to unintended data exposure and compliance issues.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

This command sends prompt content to Freepik over the network using an API key, which creates an external data-transmission path. While expected for the feature, it becomes security-relevant because user prompts or embedded asset metadata may contain sensitive or proprietary information, and the skill does not pair the transmission with a clear consent/privacy warning.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

  • Freepik high-fidelity product image (Mystic):
bash
curl -s -X POST "https://api.freepik.com/v1/ai/mystic" \
  -H "x-freepik-api-key: $FREEPIK_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"prompt":"Studio product shot of matte black earbuds on reflective surface","resolution":"2k","styling":{"style":"photo"}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

This command sends prompt content to Freepik over the network using an API key, which creates an external data-transmission path. While expected for the feature, it becomes security-relevant because user prompts or embedded asset metadata may contain sensitive or proprietary information, and the skill does not pair the transmission with a clear consent/privacy warning.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

  • Freepik high-fidelity product image (Mystic):
bash
curl -s -X POST "https://api.freepik.com/v1/ai/mystic" \
  -H "x-freepik-api-key: $FREEPIK_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"prompt":"Studio product shot of matte black earbuds on reflective surface","resolution":"2k","styling":{"style":"photo"}}'

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Using npx create-video@latest executes an unpinned package from the registry, so future upstream changes or a compromised dependency could run unexpected code on the user's machine. In this skill context, the command is presented as part of the normal workflow, which increases the chance of silent supply-chain exposure during video assembly.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · creative-output/dry-run-freepik-first/commands/freepik-task-plan.json (reported line 5)May include surrounding context.

json
{
    "step": "asset_scene_1",
    "provider": "freepik",
    "command": "curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{\"prompt\":\"Create a 45-second product marketing video for an AI note-taking app for founders. Hook scene, 16:9, modern cinematic lighting.\",\"resolution\":\"2k\",\"styling\":{\"style\":\"photo\"}}'"
  },
  {
    "step": "asset_scene_2",

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This command transmits generation prompts to an external Freepik API, which is a real data egress event. In context this is part of the intended function of a creative-production skill, but it still creates privacy and data-governance risk if prompts include confidential customer, product, or campaign information.

Content

Scanner excerpt · creative-output/dry-run-freepik-first/commands/run-freepik-first.sh (reported line 12)May include surrounding context.

sh
mkdir -p ./creative-output/{assets,scenes,audio,final,manifests}

echo "=== asset_scene_1 (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Create a 45-second product marketing video for an AI note-taking app for founders. Hook scene, 16:9, modern cinematic lighting.","resolution":"2k","styling":{"style":"photo"}}'

echo "=== asset_scene_2 (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Create a 45-second product marketing video for an AI note-taking app for founders. Pain scene, 16:9, modern cinematic lighting.","resolution":"2k","styling":{"style":"photo"}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This command transmits generation prompts to an external Freepik API, which is a real data egress event. In context this is part of the intended function of a creative-production skill, but it still creates privacy and data-governance risk if prompts include confidential customer, product, or campaign information.

Content

Scanner excerpt · creative-output/dry-run-freepik-first/commands/run-freepik-first.sh (reported line 12)May include surrounding context.

sh
mkdir -p ./creative-output/{assets,scenes,audio,final,manifests}

echo "=== asset_scene_1 (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Create a 45-second product marketing video for an AI note-taking app for founders. Hook scene, 16:9, modern cinematic lighting.","resolution":"2k","styling":{"style":"photo"}}'

echo "=== asset_scene_2 (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Create a 45-second product marketing video for an AI note-taking app for founders. Pain scene, 16:9, modern cinematic lighting.","resolution":"2k","styling":{"style":"photo"}}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script silently sends prompts for image, video, voiceover, and music generation to a third-party service with only minimal progress labels. In a creative skill, outbound transmission is expected, but the lack of explicit disclosure is still risky because user prompts, brand material, or sensitive project details could be sent off-platform without informed user awareness.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This command sends another prompt to Freepik for content generation, creating additional external transmission of project data. Repeated calls increase exposure because multiple scene descriptions are disclosed to a third party, potentially revealing campaign structure or internal product messaging.

Content

Scanner excerpt · creative-output/dry-run-freepik-first/commands/run-freepik-first.sh (reported line 15)May include surrounding context.

sh
curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Create a 45-second product marketing video for an AI note-taking app for founders. Hook scene, 16:9, modern cinematic lighting.","resolution":"2k","styling":{"style":"photo"}}'

echo "=== asset_scene_2 (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Create a 45-second product marketing video for an AI note-taking app for founders. Pain scene, 16:9, modern cinematic lighting.","resolution":"2k","styling":{"style":"photo"}}'

echo "=== asset_scene_3 (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Create a 45-second product marketing video for an AI note-taking app for founders. Reveal scene, 16:9, modern cinematic lighting.","resolution":"2k","styling":{"style":"photo"}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This request transmits another scene prompt to Freepik, continuing third-party disclosure of creative brief content. Although aligned with the skill's purpose, the transmission may expose proprietary marketing concepts or sensitive product descriptions if reused with real user input.

Content

Scanner excerpt · creative-output/dry-run-freepik-first/commands/run-freepik-first.sh (reported line 18)May include surrounding context.

sh
curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Create a 45-second product marketing video for an AI note-taking app for founders. Pain scene, 16:9, modern cinematic lighting.","resolution":"2k","styling":{"style":"photo"}}'

echo "=== asset_scene_3 (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Create a 45-second product marketing video for an AI note-taking app for founders. Reveal scene, 16:9, modern cinematic lighting.","resolution":"2k","styling":{"style":"photo"}}'

echo "=== asset_scene_4 (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Create a 45-second product marketing video for an AI note-taking app for founders. Features scene, 16:9, modern cinematic lighting.","resolution":"2k","styling":{"style":"photo"}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This outbound API call shares another scene-generation prompt with a third party. The risk is not code execution but loss of confidentiality and compliance issues when external AI providers receive business-sensitive prompt content.

Content

Scanner excerpt · creative-output/dry-run-freepik-first/commands/run-freepik-first.sh (reported line 21)May include surrounding context.

sh
curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Create a 45-second product marketing video for an AI note-taking app for founders. Reveal scene, 16:9, modern cinematic lighting.","resolution":"2k","styling":{"style":"photo"}}'

echo "=== asset_scene_4 (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Create a 45-second product marketing video for an AI note-taking app for founders. Features scene, 16:9, modern cinematic lighting.","resolution":"2k","styling":{"style":"photo"}}'

echo "=== asset_scene_5 (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Create a 45-second product marketing video for an AI note-taking app for founders. Proof scene, 16:9, modern cinematic lighting.","resolution":"2k","styling":{"style":"photo"}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This line sends additional prompt data to Freepik for image generation. Each extra call broadens the amount of campaign narrative and product positioning shared externally, which can matter in pre-launch or confidential marketing contexts.

Content

Scanner excerpt · creative-output/dry-run-freepik-first/commands/run-freepik-first.sh (reported line 24)May include surrounding context.

sh
curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Create a 45-second product marketing video for an AI note-taking app for founders. Features scene, 16:9, modern cinematic lighting.","resolution":"2k","styling":{"style":"photo"}}'

echo "=== asset_scene_5 (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Create a 45-second product marketing video for an AI note-taking app for founders. Proof scene, 16:9, modern cinematic lighting.","resolution":"2k","styling":{"style":"photo"}}'

echo "=== asset_scene_6 (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Create a 45-second product marketing video for an AI note-taking app for founders. CTA scene, 16:9, modern cinematic lighting.","resolution":"2k","styling":{"style":"photo"}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This is another external generation request that exposes part of the creative brief to Freepik. In a creative asset skill this is expected behavior, but still a real egress pathway that should be transparent and permissioned.

Content

Scanner excerpt · creative-output/dry-run-freepik-first/commands/run-freepik-first.sh (reported line 27)May include surrounding context.

sh
curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Create a 45-second product marketing video for an AI note-taking app for founders. Proof scene, 16:9, modern cinematic lighting.","resolution":"2k","styling":{"style":"photo"}}'

echo "=== asset_scene_6 (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Create a 45-second product marketing video for an AI note-taking app for founders. CTA scene, 16:9, modern cinematic lighting.","resolution":"2k","styling":{"style":"photo"}}'

echo "=== asset_scene_7 (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Create a 45-second product marketing video for an AI note-taking app for founders. Hook scene, 16:9, modern cinematic lighting.","resolution":"2k","styling":{"style":"photo"}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This request continues the sequence of external prompt submissions to Freepik. If adapted to user-supplied prompts, it could unintentionally leak confidential product strategy, unreleased campaign details, or regulated content to the provider.

Content

Scanner excerpt · creative-output/dry-run-freepik-first/commands/run-freepik-first.sh (reported line 30)May include surrounding context.

sh
curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Create a 45-second product marketing video for an AI note-taking app for founders. CTA scene, 16:9, modern cinematic lighting.","resolution":"2k","styling":{"style":"photo"}}'

echo "=== asset_scene_7 (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Create a 45-second product marketing video for an AI note-taking app for founders. Hook scene, 16:9, modern cinematic lighting.","resolution":"2k","styling":{"style":"photo"}}'

echo "=== asset_scene_8 (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Create a 45-second product marketing video for an AI note-taking app for founders. Pain scene, 16:9, modern cinematic lighting.","resolution":"2k","styling":{"style":"photo"}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This line sends yet another scene prompt to Freepik, extending external disclosure of content-generation instructions. The risk remains primarily privacy and governance rather than direct compromise, but it is still a true security-relevant transmission.

Content

Scanner excerpt · creative-output/dry-run-freepik-first/commands/run-freepik-first.sh (reported line 33)May include surrounding context.

sh
curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Create a 45-second product marketing video for an AI note-taking app for founders. Hook scene, 16:9, modern cinematic lighting.","resolution":"2k","styling":{"style":"photo"}}'

echo "=== asset_scene_8 (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Create a 45-second product marketing video for an AI note-taking app for founders. Pain scene, 16:9, modern cinematic lighting.","resolution":"2k","styling":{"style":"photo"}}'

echo "=== video_scene_1 (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/video/kling-v3-omni-pro -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Animate scene 1 with cinematic product motion","duration":5}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This API call submits a video-animation prompt to Freepik's video generation endpoint. Beyond prompt disclosure, media-generation requests may also trigger billing and third-party processing of creative assets, so users should be clearly informed before execution.

Content

Scanner excerpt · creative-output/dry-run-freepik-first/commands/run-freepik-first.sh (reported line 36)May include surrounding context.

sh
curl -s -X POST https://api.freepik.com/v1/ai/mystic -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Create a 45-second product marketing video for an AI note-taking app for founders. Pain scene, 16:9, modern cinematic lighting.","resolution":"2k","styling":{"style":"photo"}}'

echo "=== video_scene_1 (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/video/kling-v3-omni-pro -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Animate scene 1 with cinematic product motion","duration":5}'

echo "=== video_scene_3 (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/video/kling-v3-omni-pro -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Animate scene 3 with cinematic product motion","duration":5}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This line performs another outbound video-generation request to Freepik. Multiple automated calls amplify exposure and cost risk, especially if the script is run in unattended mode or against user-provided prompts.

Content

Scanner excerpt · creative-output/dry-run-freepik-first/commands/run-freepik-first.sh (reported line 39)May include surrounding context.

sh
curl -s -X POST https://api.freepik.com/v1/ai/video/kling-v3-omni-pro -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Animate scene 1 with cinematic product motion","duration":5}'

echo "=== video_scene_3 (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/video/kling-v3-omni-pro -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Animate scene 3 with cinematic product motion","duration":5}'

echo "=== video_scene_5 (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/video/kling-v3-omni-pro -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Animate scene 5 with cinematic product motion","duration":5}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This is another third-party video-generation transmission. In context the behavior is functional, not overtly malicious, but lack of controls means the script can silently send several requests and associated creative intent to an external service.

Content

Scanner excerpt · creative-output/dry-run-freepik-first/commands/run-freepik-first.sh (reported line 42)May include surrounding context.

sh
curl -s -X POST https://api.freepik.com/v1/ai/video/kling-v3-omni-pro -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Animate scene 3 with cinematic product motion","duration":5}'

echo "=== video_scene_5 (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/video/kling-v3-omni-pro -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Animate scene 5 with cinematic product motion","duration":5}'

echo "=== video_scene_7 (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/video/kling-v3-omni-pro -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Animate scene 7 with cinematic product motion","duration":5}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This line sends an additional animation prompt to Freepik. The cumulative effect of many outbound calls makes the skill more dangerous in practice because it increases both confidentiality exposure and accidental spend without strong operator visibility.

Content

Scanner excerpt · creative-output/dry-run-freepik-first/commands/run-freepik-first.sh (reported line 45)May include surrounding context.

sh
curl -s -X POST https://api.freepik.com/v1/ai/video/kling-v3-omni-pro -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Animate scene 5 with cinematic product motion","duration":5}'

echo "=== video_scene_7 (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/video/kling-v3-omni-pro -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Animate scene 7 with cinematic product motion","duration":5}'

echo "=== voiceover (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/voiceover/elevenlabs-turbo-v2-5 -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"text":"Replace with stitched scene narration","voice_id":"21m00Tcm4TlvDq8ikWAM"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This request sends voiceover text and a voice identifier to an external provider via Freepik. Voiceover text may contain scripts, customer names, or unreleased messaging, so sending it externally without explicit disclosure can create privacy and confidentiality issues.

Content

Scanner excerpt · creative-output/dry-run-freepik-first/commands/run-freepik-first.sh (reported line 48)May include surrounding context.

sh
curl -s -X POST https://api.freepik.com/v1/ai/video/kling-v3-omni-pro -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"Animate scene 7 with cinematic product motion","duration":5}'

echo "=== voiceover (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/voiceover/elevenlabs-turbo-v2-5 -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"text":"Replace with stitched scene narration","voice_id":"21m00Tcm4TlvDq8ikWAM"}'

echo "=== music (freepik) ==="
curl -s -X POST https://api.freepik.com/v1/ai/music-generation -H 'x-freepik-api-key: $FREEPIK_API_KEY' -H 'Content-Type: application/json' -d '{"prompt":"upbeat modern product marketing background music","music_length_seconds":45}'

Static analysis

No suspicious patterns detected.