Back to skill

Security audit

GifHorse

Security checks for vulnerabilities and agentic risk

Overview

GifHorse’s stated purpose is coherent, but its install path runs mutable third-party code from an unpinned GitHub branch before the reviewed package can verify what users are installing.

Review the upstream GitHub repository before installing, prefer a pinned commit or signed release if available, and avoid automatic subtitle downloads or iMessage sending for sensitive videos unless you are comfortable sharing related metadata or generated media.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:5
Finding

Unpinned Remote Repository Installation Enables Supply-Chain Code Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 5
Vulnerability Type: T08: Insecure Dependencies
Risk Level: High

Vulnerable Code

sh
git clone https://github.com/Coyote-git/gifhorse.git ~/gifhorse && cd ~/gifhorse && python3 -m venv venv && source venv/bin/activate && pip install -e .

Technical Analysis

The installation command clones the current state of a remote Git repository without pinning an audited commit, signed tag, release artifact, or cryptographic checksum. It then runs pip install -e ., which installs the retrieved project in editable mode and may execute package build or installation logic.

Consequently, the code executed by users can differ from the code that existed when this Skill was reviewed. The remote implementation and its transitive Python dependencies are not included in the audited artifact, so their behavior cannot be verified from this project. Compromise of the upstream account, repository, or dependency chain could turn the documented installation process into an arbitrary-code-execution channel.

Although network-dependent subtitle retrieval and optional iMessage delivery are disclosed as part of the Skill's functionality, the unpinned installation source is not necessary to provide those features and exceeds a safely reproducible trust boundary.

Attack Path

  1. An attacker compromises the upstream repository, its maintainer account, or a dependency referenced by the project.
  2. The attacker adds malicious package installation or runtime logic to the branch cloned by default.
  3. A user invokes the Skill's documented installation command.
  4. Git retrieves the attacker-controlled repository state because no immutable revision is specified.
  5. pip install -e . processes and installs the retrieved package, potentially executing malicious build or installation logic.
  6. The installed gifhorse command can subsequently ...[truncated 860 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin installation to a specific, reviewed Git commit or immutable signed release rather than the repository's mutable default branch.
  2. Verify the release artifact using a cryptographic checksum or a trusted signature before installation.
  3. Replace editable installation with installation from an immutable, versioned artifact intended for end users.
  4. Lock all direct and transitive Python dependencies to reviewed versions and verify them with hashes.
  5. Prefer vendoring the required implementation in the Skill package when feasible so the executed code can be audited together with the Skill.
  6. Document the exact external services contacted for subtitle retrieval, the metadata transmitted, and applicable privacy implications.
  7. Require explicit user confirmation before sending generated media through iMessage or transmitting media-derived information to external services.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly states that transcription 'downloads subtitles automatically' from online providers, which causes user file metadata and viewing-library details to be transmitted over the network without any privacy or network-use warning. In this context, users may reasonably expect a local media-processing workflow, so the undisclosed external fetch behavior increases the risk of accidental data exposure and unexpected network activity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents --send and --send-to options for sending generated GIFs via iMessage but does not warn that this shares generated media externally to another recipient. Because the content is derived from a user's local video library and may contain copyrighted, sensitive, or embarrassing material, omission of a sharing warning can lead to unintended disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.