Back to skill

Security audit

ReelClaw

Security checks for vulnerabilities and agentic risk

Overview

ReelClaw has a coherent video-production purpose, but it needs review because it can make persistent system changes, upload videos to third parties including a public host, spend service credits, and publish to real social accounts.

Install only if you are comfortable giving this skill access to DanSUGC, Gemini, local video files, and social posting workflows. Require manual approval before any sudo/package install, font download, media upload, credit-spending purchase, public tmpfiles.org upload, or publish/update/delete action, and use non-sensitive demo footage with restricted API keys and test social accounts where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T08 · Insecure Dependencies

Error
Location
SKILL.md:82
Finding

Unverified Remote Font Archive Is Installed Without Integrity Validation

Content
View full analysis
/dev/null && fc-cache -f "$FONT_DIR" echo "TikTok Sans: installed to $FONT_DIR" fi ``` ### Technical Analysis The mandatory preflight procedure downloads a mutable archive from a third-party font-distribution website and installs its contents without validating a cryptographic digest or signature. The archive is neither version-pinned nor restricted to a known artifact. A compromised distribution server, DNS or account takeover, or malicious upstream archive replacement could therefore change the bytes installed after the Skill has been audited. Font files are subsequently processed by `fc-cache`, FFmpeg, and operating-system font libraries. A crafted font could exploit a vulnerability in one of those parsers. The wildcard copy also accepts every matching `TikTokSans*.ttf` file rather than an explicit allowlist. The download is data retrieval rather than the `curl | bash` behavior identified by the pre-scan. No actual `curl | bash` command was found in the audited files. Nevertheless, automatically processing an unverified remote binary artifact remains a supply-chain risk. ### Attack Path 1. An ...[truncated 957 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:449
Finding

Videos Are Uploaded to Public Third-Party Hosting Without a Privacy Control

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
tools-setup.md:163
Finding

Gemini API Key Is Embedded in Request URLs

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
ffmpeg-patterns.md:57
Finding

Predictable Shared Temporary Paths Permit File Clobbering and Cross-Run Interference

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (28)

Chaining Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The chained command performs update and install with sudo in a single line, reducing opportunities for user review and making accidental or unsafe execution easier. In an agent skill context, this pattern is more dangerous because it encourages autonomous privileged system modification as part of normal task flow.

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
if command -v brew &>/dev/null; then
    brew install ffmpeg
  elif command -v apt-get &>/dev/null; then
    sudo apt-get update && sudo apt-get install -y ffmpeg
  else
    echo "ERROR: Install ffmpeg manually"; exit 1
  fi

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 176)May include surrounding context.

  1. Download using the URLs returned from purchase
bash
curl -L -o hook-clip.mp4 "DOWNLOAD_URL_FROM_PURCHASE"

Hook Selection Rules

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 383)May include surrounding context.

bash
# 1. Upload video to Gemini File API
FILE_URI=$(curl -s -X POST \
  "https://generativelanguage.googleapis.com/upload/v1beta/files?key=$GEMINI_API_KEY" \
  -H "X-Goog-Upload-Command: start, upload, finalize" \
  -H "X-Goog-Upload-Header-Content-Type: video/mp4" \

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · tools-setup.md (reported line 165)May include surrounding context.

bash
# 1. Upload video to Gemini File API
FILE_URI=$(curl -s -X POST \
  "https://generativelanguage.googleapis.com/upload/v1beta/files?key=$GEMINI_API_KEY" \
  -H "X-Goog-Upload-Command: start, upload, finalize" \
  -H "X-Goog-Upload-Header-Content-Type: video/mp4" \

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · virality-scoring.md (reported line 29)May include surrounding context.

bash
# 1. Upload video to Gemini File API
FILE_URI=$(curl -s -X POST \
  "https://generativelanguage.googleapis.com/upload/v1beta/files?key=$GEMINI_API_KEY" \
  -H "X-Goog-Upload-Command: start, upload, finalize" \
  -H "X-Goog-Upload-Header-Content-Type: video/mp4" \

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The README instructs users to run npx skills add dansugc/reelclaw --all without pinning a specific package version or commit. This creates a supply-chain risk: users may install a newer or compromised package than the author originally intended, and --all broadens the trust boundary by pulling the full skill contents automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description advertises sourcing clips, analyzing demos with external AI, publishing to TikTok/Instagram, and tracking analytics, but does not warn about account risk, third-party data sharing, privacy implications, or the possibility of automated posting. In this context, omission is significant because the skill interfaces with external services, user media, and social accounts, so users may unknowingly expose sensitive content or authorize impactful actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

This is the same unpinned installation pattern repeated in setup instructions, increasing the chance that users will execute an unreviewed, mutable dependency. In a skill that later connects MCP servers and handles publishing workflows, mutable install instructions are more dangerous because compromise could lead to credential theft or unintended automation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example trigger phrases are broad natural-language requests like 'Find me format ideas...' and 'Find hooks for my meditation app,' which can overlap with ordinary conversation. In agents that auto-dispatch skills based on matching user phrasing, this can cause unintended invocation of a powerful skill that performs research, analytics, or publishing-related actions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill directs the agent to install host software and fonts, including package-manager and privileged operations, rather than limiting itself to the declared workflow. This expands the skill’s authority over the local system and creates avoidable risk from unauthorized system modification, supply-chain compromise, or privilege escalation during routine use.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
98% confidence
Finding

The skill instructs use of sudo to install ffmpeg automatically on the host. Embedding privileged execution in a routine content-production skill is dangerous because it can alter the system with elevated rights, magnifying the impact of mistakes, malicious package substitution, or execution in environments where the agent should remain unprivileged.

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
if command -v brew &>/dev/null; then
    brew install ffmpeg
  elif command -v apt-get &>/dev/null; then
    sudo apt-get update && sudo apt-get install -y ffmpeg
  else
    echo "ERROR: Install ffmpeg manually"; exit 1
  fi

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The skill fetches a font archive from an external site and installs it locally during normal execution. Pulling executable-adjacent assets from an unvetted third-party source at runtime increases supply-chain risk and writes untrusted content onto the host without strong provenance or integrity checks.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

md
fi
  mkdir -p "$FONT_DIR"
  cd /tmp
  curl -L -o tiktoksans.zip "https://www.cufonfonts.com/download/font/tiktok-sans"
  unzip -o tiktoksans.zip -d tiktoksans_extracted
  cp tiktoksans_extracted/TikTokSans*.ttf "$FONT_DIR/"
  rm -rf tiktoksans_extracted tiktoksans.zip

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 176)May include surrounding context.

  1. Download using the URLs returned from purchase
bash
curl -L -o hook-clip.mp4 "DOWNLOAD_URL_FROM_PURCHASE"

Hook Selection Rules

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 383)May include surrounding context.

bash
# Upload to Gemini
FILE_URI=$(curl -s -X POST \
  "https://generativelanguage.googleapis.com/upload/v1beta/files?key=$GEMINI_API_KEY" \
  -H "X-Goog-Upload-Command: start, upload, finalize" \
  -H "X-Goog-Upload-Header-Content-Type: video/mp4" \

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill introduces tmpfiles.org as an undeclared third-party service to make generated videos publicly reachable for publishing. This silently broadens data sharing beyond the declared services and can expose unpublished or sensitive media to a public host outside the user’s expected trust boundary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow uploads generated video to a public temporary hosting service without a clear privacy warning or confirmation step. Users may assume the content stays within DanSUGC/Gemini, but the reel becomes accessible through a public URL, creating risk of unintended disclosure, scraping, or reuse before scheduled publication.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example uploads a generated video to tmpfiles.org and prints a public download URL, but it does not warn that this discloses the file to a third-party external service. In this skill's context, the files may contain unreleased marketing assets, user-generated content, or other sensitive media, so users could accidentally expose data outside their controlled publishing pipeline.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guide describes tools that can publish, update, and delete social media posts but does not include an explicit warning that these actions can affect live user accounts. In an agent-skill context, omission of such warnings increases the risk of accidental destructive or reputation-impacting actions because an agent may treat these capabilities as routine automation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The Gemini setup instructs users to upload local video files to Google's API but does not explicitly warn that the full video content leaves the local environment and is transmitted to a third party. In this skill's context, demo recordings may contain proprietary UI, customer data, or credentials, making silent external upload materially risky.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This command uploads a local video file to an external Google endpoint, creating a direct data exfiltration path from the user's machine to a third-party service. Even though the intended use is legitimate video analysis, the mechanism can expose sensitive internal recordings if used without informed consent and sanitization.

Content

Scanner excerpt · tools-setup.md (reported line 165)May include surrounding context.

Direct video upload for analysis:

bash
# Step 1: Upload video file
FILE_URI=$(curl -s -X POST \
  "https://generativelanguage.googleapis.com/upload/v1beta/files?key=$GEMINI_API_KEY" \
  -H "X-Goog-Upload-Command: start, upload, finalize" \
  -H "X-Goog-Upload-Header-Content-Type: video/mp4" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This request sends prompts and a file reference to an external model endpoint for analysis, which means user-provided content and instructions are processed by a third party. In combination with the prior upload step, it expands external exposure of potentially sensitive video-derived information.

Content

Scanner excerpt · tools-setup.md (reported line 173)May include surrounding context.

md
--data-binary @"DEMO.mp4" | python3 -c "import sys,json; print(json.load(sys.stdin)['file']['uri'])")

# Step 2: Analyze
curl -s "https://generativelanguage.googleapis.com/v1beta/models/gemini-3.1-flash-lite-preview:generateContent?key=$GEMINI_API_KEY" \
  -H "Content-Type: application/json" \
  -d "{
    \"contents\": [{

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This command transmits the contents of a local MP4 file to an external API endpoint, which is a genuine external data transfer. While this appears functionally necessary for cloud video analysis, it is still security-relevant because the file contents leave the local environment and may contain sensitive or proprietary material.

Content

Scanner excerpt · virality-scoring.md (reported line 29)May include surrounding context.

bash
# 1. Upload video to Gemini File API
FILE_URI=$(curl -s -X POST \
  "https://generativelanguage.googleapis.com/upload/v1beta/files?key=$GEMINI_API_KEY" \
  -H "X-Goog-Upload-Command: start, upload, finalize" \
  -H "X-Goog-Upload-Header-Content-Type: video/mp4" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly uploads a local video file to Google's Gemini File API but does not include any user-facing warning or consent step about sending reel contents to a third-party service. This creates a real privacy and data-governance risk because videos may contain proprietary marketing assets, personal data, or unpublished content that is transmitted off-host without clear disclosure.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 213)May include surrounding context.

md
# 3. Score with Gemini
VIRALITY_PROMPT=$(cat /tmp/virality_prompt.txt)
curl -s "https://generativelanguage.googleapis.com/v1beta/models/gemini-3.1-flash-lite-preview:generateContent?key=$GEMINI_API_KEY" \
  -H "Content-Type: application/json" \
  -d "{
    \"contents\": [{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 393)May include surrounding context.

md
# 3. Score with Gemini
VIRALITY_PROMPT=$(cat /tmp/virality_prompt.txt)
curl -s "https://generativelanguage.googleapis.com/v1beta/models/gemini-3.1-flash-lite-preview:generateContent?key=$GEMINI_API_KEY" \
  -H "Content-Type: application/json" \
  -d "{
    \"contents\": [{

Static analysis

No suspicious patterns detected.