Back to skill

Security audit

QCut Toolkit

Security checks for vulnerabilities and agentic risk

Overview

This QCut media toolkit includes useful media workflows, but it also contains unsafe local servers, public media uploads, plaintext credential handling, and a self-updating sub-skill that require careful review before installation.

Install only in a controlled environment after reviewing the sub-skills. Do not use it on confidential audio or video unless you are comfortable sending media to public hosting and cloud AI providers. Avoid the self-evolve sub-skill, do not place secrets under .claude/skills, and do not run the review servers on networks where other devices or webpages could reach them.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (6)

T09 · Insecure Skill Coding Practices

Error
Location
videocut/talk-edit/scripts/review_server.js:31
Finding

Unauthenticated Review Server Exposes Local Project Files and Video-Cutting Operations

Content
View full analysis
{ // CORS res.setHeader("Access-Control-Allow-Origin", "*"); res.setHeader("Access-Control-Allow-Methods", "GET, POST, OPTIONS"); res.setHeader("Access-Control-Allow-Headers", "Content-Type"); // API: execute cut if (req.method === "POST" && req.url === "/api/cut") { let body = ""; req.on("data", (chunk) => (body += chunk)); req.on("end", () => { try { const deleteList = JSON.parse(body); fs.writeFileSync( "delete_segments.json", JSON.stringify(deleteList, null, 2) ); const scriptPath = path.join(__dirname, "cut_video.sh"); execFileSync( "bash", [scriptPath, VIDEO_FILE, "delete_segments.json", outputFile], { stdio: "inherit" } ); // ... } }); return; } // Static file service from the entire current directory const baseDir = path.resolve("."); let filePath = req.url === "/" ? "/review.html" : req.url; filePath = path.resolve("." + filePath); // ... const stream = fs.createReadStream(filePath); stream.pipe(res); }); server.listen(PORT, () => { // ... }); ``` ### Technical Analysis Calling `server.listen(PORT)` without specifying a loopback address normally binds the Node.js HTTP server to the unspecified address, potentially exposing it on all available network interfaces. The server has no authentication, session token, origin validation, or request authorization. The static-file route exposes every readable file beneath the process's current working directory rather than an explicit allowlist such as `review.html`, `audio.mp3`, and the selected video. If the serve ...[truncated 2037 chars]
Remediation
View remediation
{ console.log(`Review server: http://127.0.0.1:${PORT}`); }); ``` 2. Remove wildcard CORS. Prefer no CORS header for a same-origin application. If cross-origin access is necessary, allow only a specific trusted origin. 3. Generate a cryptographically random session token at startup and require it on every API request. 4. Serve only explicit files through dedicated routes. Do not map arbitrary URLs to the current working directory. 5. Add a strict request-body limit and reject the connection when it is exceeded. 6. Validate that `deleteList` is an array of bounded objects containing finite numeric `start` and `end` values. 7. Reject overlapping, negative, non-finite, excessively large, or out-of-duration ranges. 8. Add operation locking and rate limiting so only one cut operation can execute at a time. 9. Run media processing with restricted filesystem permissions and from a dedicated working directory containing no credentials. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
videocut/subtitles/scripts/subtitle_server.js:36
Finding

Unauthenticated Subtitle Server Exposes Video and Permits Remote File Modification and FFmpeg Execution

Content
View full analysis
{ res.setHeader("Access-Control-Allow-Origin", "*"); res.setHeader("Access-Control-Allow-Methods", "GET, POST, OPTIONS"); res.setHeader("Access-Control-Allow-Headers", "Content-Type"); if (req.url === "/api/subtitles") { res.writeHead(200, { "Content-Type": "application/json" }); res.end(JSON.stringify(subtitles)); return; } if (req.method === "POST" && req.url === "/api/save") { let body = ""; req.on("data", (chunk) => (body += chunk)); req.on("end", () => { subtitles = JSON.parse(body); fs.writeFileSync(SUBTITLES_FILE, JSON.stringify(subtitles, null, 2)); // ... }); return; } if (req.method === "POST" && req.url === "/api/burn") { let body = ""; req.on("data", (chunk) => (body += chunk)); req.on("end", () => { const { outline } = JSON.parse(body); // ... const proc = spawn("ffmpeg", args, { stdio: ["pipe", "pipe", "pipe"] }); // ... }); return; } if (req.url === "/video.mp4" && VIDEO_PATH) { const stream = fs.createReadStream(VIDEO_PATH, { start, end }); stream.pipe(res); return; } }); server.listen(PORT, () => { // ... }); ``` ### Technical Analysis The subtitle server has the same wildcard-binding and permissive-CORS issue as the review server. It exposes source video through `/video.mp4`, transcript data through `/api/subtitles`, and state-changing operations through `/api/save`, `/api/save-srt`, and `/api/burn`. No endpoint requires authentication or a per-session capability. Consequently, any client capable of reaching the port can download the selected video, replace subtitles, create output files, and ...[truncated 1588 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
videocut/talk-edit/scripts/cut_video.sh:37
Finding

Shell/JavaScript Code Injection Through the Deletion-List Filename

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
videocut/talk-edit/scripts/generate_review.js:42
Finding

Unpinned Remote JavaScript Is Executed in a Privileged Local Review Origin

Content
View full analysis
``` ### Technical Analysis The generated review page loads executable JavaScript from `unpkg.com` each time it is opened. The URL specifies only the major version (`@7`), so the served payload may change over time without any modification to the audited skill package. There is no Subresource Integrity hash, exact version pin, local vendoring, or restrictive Content Security Policy. A compromised package release, npm account, CDN, DNS path, or upstream dependency could therefore deliver modified JavaScript. The remote script executes in the origin of the local review server. It can access the review page's DOM, transcript data embedded in the page, local audio exposed by the server, and same-origin endpoints such as `/api/cut`. It may also send collected content to an external server. This is not required for the declared functionality: the reviewed Wavesurfer build can be pinned and shipped locally. ### Attack Path 1. The user generates `review.html` and starts the local review server. 2. The browser opens the page and requests `https://unpkg.com/wavesurfer.js@7`. 3. The CDN or upstream package serves a malicious or compromised build. 4. The browser executes the payload as part of the local review application. 5. The payload reads transcript and audio-related information available to the page. 6. It can invoke the local `/api/cut` endpoint or exfiltrate data to an attacker-controlled origin. ### Impact Assessment A compromised remote dependency could: - Read private transcript and review data. - Access media made available to the page. - Modify the user's review selections. - Trigger local video-cutting operations through same-origin APIs. - Exfiltrate data over the ne ...[truncated 161 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
videocut/talk-edit/SKILL.md:94
Finding

Private Audio Is Uploaded to an Anonymous Public File-Hosting Service Without a Consent or Retention Control

Content
View full analysis
/.claude/skills/qcut-toolkit/videocut/talk-edit" "$SKILL_DIR/scripts/volcengine_transcribe.sh" "https://h.uguu.se/xxx.mp3" ``` The same workflow is also documented in `videocut/subtitles/SKILL.md:39-53`. ### Technical Analysis The skill instructs the agent to extract audio from the user's video and upload it to `uguu.se`, an external public file-hosting service, solely to obtain a URL that another provider can fetch. Speech recordings and transcripts may contain personal data, confidential business discussions, biometric voice information, or unpublished content. The instructions do not require explicit informed consent before upload, describe the hosting service's retention behavior, provide deletion controls, or warn that possession of the generated URL may provide access to the media. The data is disclosed to at least two external parties: 1. The file-hosting service receives and stores the complete audio. 2. The transcription provider retrieves the audio from the public URL. The upload therefore broadens the trust boundary beyond what is minimally necessary for transcription. A provider-supported direct upload, signed private object URL, or user-controlled storage location would provide a narrower privilege and disclosure scope. ### Attack Path 1. A user asks the skill to transcribe or edit a private video. 2. The skill extracts the audio track into `audio.mp3`. 3. Following the documented mandatory workflow, the agent uploads the complete recording ...[truncated 997 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
videocut/subtitles/scripts/subtitle_server.js:484
Finding

Stored Subtitle Text Is Inserted into HTML Without Context-Appropriate Escaping

Content
View full analysis
{ if (filter && !s.text.includes(filter)) return ''; const isEditing = i === editingIdx; return `
${i + 1}. ${formatTime(s.start)} → ${formatTime(s.end)}
${isEditing ? `` : `${s.text}` }
`; }).join(''); } ``` ### Technical Analysis Subtitle text is loaded from `subtitles_with_time.json` and inserted into `innerHTML` without HTML escaping. In editing mode, it is also inserted directly into a double-quoted HTML attribute. A subtitle containing HTML markup, an event-handler attribute, or a quote that terminates the `value` attribute can inject executable browser content. The malicious text may originate from an untrusted transcription result, imported subtitle data, or a project file supplied by another party. Because the injected code runs in the local subtitle server's origin, it can call `/api/save`, `/api/save-srt`, `/api/burn`, and `/api/subtitles`, and can access the video endpoint. ### Attack Path 1. An attacker supplies a project or transcription result containing crafted subtitle text. 2. The text is stored in `subtitles_with_time.json`. 3. The user starts the subtitle server and opens the editor. 4. `renderSubtitles()` concatenates the text into an HT ...[truncated 858 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
Findings (101)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The code only provides subtitle-specific review and processing functionality: it reads a local subtitles_with_time.json file, optionally loads a dictionary, serves an HTML UI for subtitle editing, serves a video file, saves subtitle edits, generates SRT output, probes video info with ffprobe, and burns subtitles into a video via ffmpeg. While this partially overlaps with the declared 'process media with FFmpeg' aspect, it does not implement most of the prominently declared capabilities such as AI generation, QCut editor control, video prompt generation, project organization, or MCP preview testing. The declared description presents a much broader, unified toolkit than the code actually delivers, so the description materially overstates and misrepresents the skill’s behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a comprehensive media toolkit with multiple capabilities across file organization, media processing, AI generation, editor control, and prompt generation. The supplied code chunk does something much narrower: it parses an input transcription result, filters/remaps words based on deleted time segments, adds silence-gap placeholders, and outputs a subtitle JSON file. While subtitle generation is loosely related to media workflows, the primary purpose and capabilities of this code are materially more specific and limited than the declared description. This is a description-behavior mismatch because the description overstates the functionality actually implemented in this chunk.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The description uses extremely broad activation criteria such as 'any media workflow' and 'content pipeline task,' which can match many ordinary user requests. In a skill that can route to shell, networked AI services, editor control, and repository-related sub-skills, overbroad triggering materially increases the risk of unintended high-impact actions.

Content

No source excerpt is available for this finding.

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

The example explicitly selects an external model provider for video analysis, implying that user media will be processed by a third-party service. In this skill context, that is expected functionality, but the documentation still lacks notice about privacy, retention, and transmission implications, so the issue is not the model selection itself but the undocumented exposure of potentially sensitive media.

Content

Scanner excerpt · ai-content-pipeline/EXAMPLES.md (reported line 139)May include surrounding context.

md
aicp analyze-video -i video.mp4

# Specify model and output
aicp analyze-video -i video.mp4 -m gemini-3-pro -t timeline -o output/

# Quick description
aicp analyze-video -i video.mp4 -t describe

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · ai-content-pipeline/SKILL.md (reported line 27)May include surrounding context.

Recommended for Claude Code / CLI workflows:

bash
# Set FAL key persistently (secure hidden prompt, stored at ~/.config/video-ai-studio/credentials.env)
aicp set-key FAL_KEY

# Verify the key is stored

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
95% confidence
Finding

The skill explicitly shows selection of an external model (gemini-2.5-flash) for video analysis, indicating content may be routed to a third-party provider. In the context of analyzing user videos, this can expose proprietary footage, personal data, transcripts, and other sensitive content if users are not clearly informed about the external processing path.

Content

Scanner excerpt · ai-content-pipeline/SKILL.md (reported line 146)May include surrounding context.

bash
aicp analyze-video -i video.mp4
aicp analyze-video -i video.mp4 -t timeline -m gemini-2.5-flash
aicp analyze-video -i video.mp4 -t transcribe
aicp analyze-video -i video.mp4 -t describe -f json

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · seedance/seedance-skill/en/SKILL.md (reported line 8)May include surrounding context.

md
# Seedance 2.0 Video Prompt Skill

You are a Seedance 2.0 video director. The user gives you a story, you output prompts ready to paste into the Seedance/JiMeng platform.

**You have full creative freedom** — emotional pacing, shot choices, character portrayal are YOUR decisions based on the story. But you MUST follow the rules marked 🔒 below.

Self-Modification

High
Category
Rogue Agent
Confidence
99% confidence
Finding

The skill explicitly brands itself as self-evolving and able to update rules, which is a classic self-modification pattern. In agent systems, self-modification is dangerous because it can create persistence, alter safety boundaries, and make future behavior less auditable or controllable.

Content

Scanner excerpt · videocut/self-evolve/SKILL.md (reported line 2)May include surrounding context.

md
---
name: videocut-self-evolve
description: Self-evolving skills. Record user feedback, update methodology and rules. Triggers: update rules, record feedback, improve skill, 更新规则, 记录反馈, 改进skill
---

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill’s stated purpose is self-evolution and modification of internal rules, which is materially outside the parent media-toolkit scope. This creates a privilege/scope mismatch where a media-oriented skill can be invoked to alter agent behavior and persistent instruction files, enabling policy drift or persistence through an unrelated capability surface.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger list includes broad phrases like 'update rules,' 'record feedback,' and 'improve skill,' which can occur in ordinary conversation. Overbroad activation criteria increase the chance the self-modifying behavior triggers unintentionally, causing unauthorized rule changes or data retention without clear user intent.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
98% confidence
Finding

The skill’s core directive is to let the agent 'learn from mistakes and continuously improve,' implemented via updates to guidance files. Without strong guardrails, this enables adversarial persistence where user prompts or misclassifications become embedded into future operating rules.

Content

Scanner excerpt · videocut/self-evolve/SKILL.md (reported line 6)May include surrounding context.

md
description: Self-evolving skills. Record user feedback, update methodology and rules. Triggers: update rules, record feedback, improve skill, 更新规则, 记录反馈, 改进skill
---

# Self-Evolve

> Let the Agent learn from mistakes and continuously improve

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The workflow explicitly directs the agent to autonomously read and modify files like CLAUDE.md and tips files, including integrating new rules without asking clarifying questions. Unreviewed autonomous updates to instruction-bearing files are dangerous because they can introduce persistence, degrade safeguards, or encode adversarial/user-injected content into future behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documented trigger conditions around auto-tracing and updating are ambiguous about when the skill should act, which makes accidental activation and unintended writes more likely. Ambiguity is especially dangerous here because the action is persistent modification of internal guidance rather than a reversible read-only operation.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases such as '更新规则、记录反馈、改进skill' are broad and map to normal user conversation, making accidental or attacker-induced activation easy. In a skill that can modify persistent files, ambiguous activation materially increases the chance of unauthorized state changes and persistence from benign-looking dialogue.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation conditions include vague statements like user correction, 'remember this,' or discovering a new general rule, without boundaries on what qualifies or what files may be changed. Combined with automatic context analysis, this creates a wide prompt-injection surface where ordinary conversation can be reinterpreted as authorization to alter persistent instructions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented workflow enables autonomous self-modification: it tells the agent to analyze context, read target files, and integrate new rules into persistent guidance files automatically. This is dangerous because it allows indirect prompt injection and durable corruption of agent instructions, potentially changing future decisions across sessions or tasks.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

The skill directs storage of an API key in .claude/skills/.env, a location associated with agent/skill configuration. Storing credentials in this area increases the chance that secrets are accessed by other tooling, unintentionally included in support/debug output, or exposed through weak project hygiene.

Content

Scanner excerpt · videocut/setup/SKILL.md (reported line 39)May include surrounding context.

Configure in project directory .claude/skills/.env:

bash
# File path: <project>/.claude/skills/.env
VOLCENGINE_API_KEY=your_api_key_here

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

The command echo "VOLCENGINE_API_KEY=your_key" >> .claude/skills/.env directly writes a secret into a sensitive local file and may leave traces in shell history, terminal logs, and copied command transcripts. This is especially risky because the skill provides no warning, redaction guidance, or safer alternative.

Content

Scanner excerpt · videocut/setup/SKILL.md (reported line 69)May include surrounding context.

2. Configure API Key

bash
echo "VOLCENGINE_API_KEY=your_key" >> .claude/skills/.env

3. Verify Environment

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
97% confidence
Finding

The verification step reads from .claude/skills/.env, which is an agent configuration area likely to contain secrets. Even though the command filters for VOLCENGINE, it still normalizes direct inspection of sensitive config files and could expose credentials in terminal output, logs, screenshots, or downstream agent context.

Content

Scanner excerpt · videocut/setup/SKILL.md (reported line 77)May include surrounding context.

bash
node -v
ffmpeg -version
cat .claude/skills/.env | grep VOLCENGINE

FAQ

Credential Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

Displaying .claude/skills/.env content with cat ... | grep VOLCENGINE can reveal whether a credential exists and may print the full API key value. In the context of a setup skill, this makes the issue more dangerous because users are likely to follow the command verbatim during onboarding, exposing secrets unnecessarily.

Content

Scanner excerpt · videocut/setup/SKILL.md (reported line 77)May include surrounding context.

bash
node -v
ffmpeg -version
cat .claude/skills/.env | grep VOLCENGINE

FAQ

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

Writing VOLCENGINE_API_KEY directly into .claude/skills/.env places a credential in plaintext inside a path associated with agent skills. This creates a clear credential exposure risk through accidental commits, file reads by other tools, backups, or later troubleshooting commands that inspect the file.

Content

Scanner excerpt · videocut/setup/SKILL_CN.md (reported line 64)May include surrounding context.

2. 配置 API Key

bash
echo "VOLCENGINE_API_KEY=your_key" >> .claude/skills/.env

3. 验证环境

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
95% confidence
Finding

The command cat .claude/skills/.env | grep VOLCENGINE explicitly reads from the agent configuration area and reveals whether a credential-bearing variable is present. In this skill context, access to .claude/skills is more dangerous because that directory may contain other secrets or agent state, and normalizing reads from it teaches a pattern that can be extended to secret exfiltration.

Content

Scanner excerpt · videocut/setup/SKILL_CN.md (reported line 72)May include surrounding context.

bash
node -v
ffmpeg -version
cat .claude/skills/.env | grep VOLCENGINE

常见问题

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The verification step reads the .env file from the skills directory, which can expose credentials or normalize inspecting secret files during routine setup. Even though grep VOLCENGINE may only show the matching line, that line itself contains the API key unless additional masking is used.

Content

Scanner excerpt · videocut/setup/SKILL_CN.md (reported line 72)May include surrounding context.

bash
node -v
ffmpeg -version
cat .claude/skills/.env | grep VOLCENGINE

常见问题

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · videocut/subtitles/SKILL.md (reported line 6)May include surrounding context.

md
description: Subtitle generation and burn-in. Volcengine transcription → dictionary correction → review → burn-in. Triggers: add subtitles, generate subtitles, 加字幕, 生成字幕, 字幕
---

<!--
input: Video file
output: Video with burned-in subtitles
pos: Post-processing skill, called after editing is complete

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill uploads audio to a public temporary hosting service without any warning that the user's media-derived audio will be shared externally. Audio often contains personal, confidential, or copyrighted material, so silent transfer to a public host creates a significant privacy and compliance risk.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
videocut/subtitles/scripts/subtitle_server.js:218

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
videocut/talk-edit/scripts/review_server.js:74