Back to skill

Security audit

Bravado

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently creates product videos from public URLs or repositories, with expected network, file-output, and rendering behavior.

Install only if you are comfortable giving it public project URLs and letting it make network requests to the site, GitHub, and Google-hosted font files. Use an empty output directory, review generated files before sharing, and pin dependencies more tightly if you need strict reproducibility.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the skill primarily performs filesystem bootstrapping and template copying while claiming to inspect sites and create finished media, users may overtrust it with repositories, URLs, or output expectations it cannot safely satisfy. Security-wise, misleading descriptions obscure the true effect of file operations and can mask unexpected writes or setup steps that should be separately reviewed.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

If the skill primarily performs filesystem bootstrapping and template copying while claiming to inspect sites and create finished media, users may overtrust it with repositories, URLs, or output expectations it cannot safely satisfy. Security-wise, misleading descriptions obscure the true effect of file operations and can mask unexpected writes or setup steps that should be separately reviewed.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the skill primarily performs filesystem bootstrapping and template copying while claiming to inspect sites and create finished media, users may overtrust it with repositories, URLs, or output expectations it cannot safely satisfy. Security-wise, misleading descriptions obscure the true effect of file operations and can mask unexpected writes or setup steps that should be separately reviewed.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the skill primarily performs filesystem bootstrapping and template copying while claiming to inspect sites and create finished media, users may overtrust it with repositories, URLs, or output expectations it cannot safely satisfy. Security-wise, misleading descriptions obscure the true effect of file operations and can mask unexpected writes or setup steps that should be separately reviewed.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill instructs the agent to use network access, shell commands, and file read/write operations, but it declares no explicit tool scope or permission boundaries. That creates an overbroad execution surface where a caller or downstream runtime may permit powerful actions without clear constraints, increasing the chance of unintended network access, filesystem modification, or command execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill metadata uses broad, generic phrasing like 'Turn a project link into a choreographed motion film' and a default prompt that activates on a wide range of requests involving project URLs, videos, explainers, or animated stories. Combined with allow_implicit_invocation: true, this increases the chance the agent is invoked when the user did not explicitly intend to run this skill, which can trigger unintended external inspection of websites or repositories and unnecessary downstream actions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · assets/starter/inspect_source.py (reported line 48)May include surrounding context.

python
parts=[p for p in parsed.path.split('/') if p]
        if len(parts)<2:raise ValueError('Provide a GitHub repository URL, not just a user profile')
        owner,repo=parts[:2];output['source_type']='github_repository'
        api=f'https://api.github.com/repos/{owner}/{repo}'
        body,final=get(api);data=json.loads(body)
        output.update({'redirected_url':final,'name':data.get('name'),'description':data.get('description'),
                       'homepage':data.get('homepage'),'default_branch':data.get('default_branch'),

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · assets/starter/inspect_source.py (reported line 54)May include surrounding context.

python
parts=[p for p in parsed.path.split('/') if p]
        if len(parts)<2:raise ValueError('Provide a GitHub repository URL, not just a user profile')
        owner,repo=parts[:2];output['source_type']='github_repository'
        api=f'https://api.github.com/repos/{owner}/{repo}'
        body,final=get(api);data=json.loads(body)
        output.update({'redirected_url':final,'name':data.get('name'),'description':data.get('description'),
                       'homepage':data.get('homepage'),'default_branch':data.get('default_branch'),

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · assets/starter/render.py (reported line 320)May include surrounding context.

python
with wave.open(str(OUT/'sound-design.wav'),'wb') as w:
        w.setnchannels(2);w.setsampwidth(2);w.setframerate(sr);w.writeframes((np.clip(a,-1,1)*32767).astype('<i2').tobytes())
    normalized=OUT/'sound-normalized.wav'
    subprocess.run(['ffmpeg','-y','-v','error','-i',str(OUT/'sound-design.wav'),'-af','loudnorm=I=-18:TP=-1.5:LRA=9','-ar','48000',str(normalized)],check=True)
    normalized.replace(OUT/'sound-design.wav')

def main():

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · assets/starter/render.py (reported line 343)May include surrounding context.

python
name=''.join(ch.lower() if ch.isalnum() else '-' for ch in b('brand','name')).strip('-')
    output=OUT/f'{name}-bravado.mp4'
    cmd=['ffmpeg','-y','-v','error','-f','rawvideo','-pix_fmt','rgb24','-s',f'{W}x{H}','-r',str(FPS),'-i','-', '-i',str(OUT/'sound-design.wav'),'-c:v','libx264','-preset','fast','-crf','18','-pix_fmt','yuv420p','-c:a','aac','-b:a','192k','-movflags','+faststart','-t',str(DURATION),str(output)]
    p=subprocess.Popen(cmd,stdin=subprocess.PIPE)
    for i in range(FPS*DURATION):
        p.stdin.write(frame(i/FPS).tobytes())
        if i%150==0:print(f'Rendered {i}/{FPS*DURATION} frames',flush=True)

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill tells the agent to inspect external websites and GitHub repositories but does not warn that this involves network access and potential transmission of request metadata to third parties. In a skill centered on analyzing public URLs this is contextually expected, which lowers severity, but users still deserve clear notice because even public-link retrieval can have privacy and compliance implications.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: Pillow has 16 known advisory(ies) (CVE-2016-2533 (Pillow buffer overflow in ImagingPcdDecode); CVE-2023-50447 (Arbitrary Code Execution in Pillow); CVE-2021-27922 (Pillow Uncontrolled Resource Consumption) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: numpy has 16 known advisory(ies) (CVE-2014-1859 (Numpy arbitrary file write via symlink attack); CVE-2021-41495 (NumPy NULL Pointer Dereference); CVE-2021-33430 (NumPy Buffer Overflow (Disputed)) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.