Back to skill

Security audit

ShellBot Product Video

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Remotion product-video skill with ordinary developer-tool and external-service cautions, not hidden or malicious behavior.

Install only if you want a Remotion-based product marketing video workflow. Use a normal project sandbox, review generated assets before sharing them with Freepik, ElevenLabs, Kling, AWS, or Google Cloud, and pin Remotion/npm dependencies for CI or sensitive work.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (48)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose is a video-generation/marketing-content skill using Remotion + React and AIDA-based storytelling. The actual code does not perform any video creation, React/Remotion composition, asset handling, storytelling logic, CTA construction, or Freepik integration. Instead, it packages the skill directory into distributable archives. This is a materially different primary purpose, not merely a supporting implementation detail of video generation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose is about generating marketing videos in Remotion/React with a specific AIDA narrative structure and constrained asset usage. The actual code does none of that: it contains no Remotion, React, video composition, storytelling logic, asset handling, or media generation. Instead, it is a release/publishing utility script for packaging and publishing the skill to ClawHub. This is a materially different primary purpose, not merely a supporting implementation detail for video creation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill instructs the agent to bootstrap projects, modify files, and load local references, but it declares no explicit tool scope or allowed-tools policy. That creates an authorization ambiguity where a host agent may permit broader filesystem access than intended, increasing the chance of unintended reads/writes or unsafe execution during project setup.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The documentation instructs users to run npx remotion without pinning a specific package version, which can fetch and execute whatever version is currently published. In a supply-chain compromise or malicious package update scenario, this could lead to execution of unreviewed code on the user's machine during setup.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/remotion-rules/compositions.md (reported line 117)May include surrounding context.

md
props,
  abortSignal,
}) => {
  const data = await fetch(`https://api.example.com/video/${props.videoId}`, {
    signal: abortSignal,
  }).then((res) => res.json());

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The documentation instructs users to run npx remotion without pinning an exact package version, which can fetch and execute whatever version is current at install time. If the upstream package is compromised, typosquatted, or a breaking/malicious release is published, users may execute unreviewed code on their system during setup.

Content

No source excerpt is available for this finding.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · references/remotion-rules/gifs.md (reported line 57)May include surrounding context.

Control what happens when the animation finishes:

tsx
// Loop indefinitely (default)
<AnimatedImage src={staticFile("animation.gif")} width={500} height={500} loopBehavior="loop" />

// Play once, show final frame

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The documentation recommends running npx remotion add @remotion/lottie without pinning the package version, which can cause users to execute whatever version of remotion is current at invocation time. If the upstream package or a dependency is compromised, or a breaking release is published, users may unknowingly run unreviewed code during installation or scaffolding.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The documentation tells users to run npx remotion without pinning a specific package version. npx may fetch the latest published package at execution time, which creates a supply-chain risk: a compromised upstream release or breaking change could execute unreviewed code on the user's machine or CI runner. In a skill/reference file, this is a real issue because readers are likely to copy-paste commands directly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The example uses npx remotion with no version pin, causing runtime resolution to whatever version is current at execution time. That exposes users to supply-chain compromise and unpredictable behavior, especially in automation where the command may run repeatedly over time with different downloaded code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This command invokes npx remotion without constraining the package version. If the upstream package is maliciously replaced, typo-squatted, or unexpectedly changed, the user could execute attacker-controlled code while rendering media.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

An unpinned npx remotion command makes the executed package version non-deterministic. That is a genuine supply-chain weakness because the docs encourage direct execution of code fetched from the registry at run time.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The reference instructs users to run npx remotion without pinning, which can silently change the code being executed between runs. In developer tooling and CI contexts, this can lead to arbitrary code execution from a compromised or newly published package version.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This example relies on npx remotion with no exact version, creating a real supply-chain exposure. Because npx may download and execute code immediately, a malicious or altered release could affect local systems, build agents, or render infrastructure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The command uses an unpinned npx package execution path, which is a well-known source of supply-chain and reproducibility issues. Users who follow the docs may unknowingly run newer or compromised code than what the author tested.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This snippet directs users to execute npx remotion without any version pinning. That means the content is effectively instructing execution of registry-sourced code that may change over time, which is a genuine security risk in environments where commands are trusted and automated.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.