Back to skill

Security audit

M3U8 Downloader

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent video downloader, but its included script can delete or overwrite files outside the intended download area if the output name is unsafe.

Review before installing. Use only trusted m3u8 URLs, pass a simple filename-only output name, and avoid running this in directories or environments where accidental deletion or internal-network access would be costly. The script should be fixed to validate output names, use mktemp for its work directory, restrict URL schemes and redirects, and clean up only a verified directory.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/download.sh:7
Finding

Path Traversal Allows Filesystem Modification and Potential Recursive Deletion

Content
View full analysis
Remediation
View remediation
&2 exit 1 fi ``` 2. Create the working directory with `mktemp` under a dedicated parent: ```bash DOWNLOAD_ROOT="$HOME/Downloads" WORK_DIR=$(mktemp -d "$DOWNLOAD_ROOT/.m3u8-download.XXXXXX") ``` 3. Register cleanup with a trap and only remove the directory returned by `mktemp`: ```bash cleanup() { [[ -n "${WORK_DIR:-}" && -d "$WORK_DIR" ]] && rm -rf -- "$WORK_DIR" } trap cleanup EXIT INT TERM ``` 4. Canonicalize and verify all destination paths remain under the expected download root before writing or deleting them. 5. Reject path separators, traversal components, control characters, and symbolic-link targets in caller-controlled output names. 6. Avoid unconditional overwrite behavior where possible, or require explicit caller confirmation before replacing an existing output file. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/download.sh:32
Finding

Unrestricted URL Fetching Permits Local and Internal Resource Access

Content
View full analysis
urls.txt || true # If segments are relative paths if [ ! -s urls.txt ]; then echo "$PLAYLIST" | grep -E "\.ts$" | while read -r line; do if [[ "$line" == /* ]]; then PROTOCOL=$(echo "$PLAYLIST_URL" | grep -oE "^https?://[^/]+") echo "${PROTOCOL}${line}" elif [[ "$line" == http* ]]; then echo "$line" else echo "${BASE_URL}/${line}" fi done > urls.txt fi ``` ### Technical Analysis The script accepts the initial playlist URL without validating its URI scheme, hostname, resolved address, or destination port. `curl -L` follows redirects without checking whether the redirect target remains an approved public HTTPS endpoint. A remote playlist can also control nested playlist, encryption-key, and segment destinations. These destinations are fetched using the host's network access through `curl` and `aria2c`. There are no protections against requests to: - Loopback addresses. - RFC 1918 private networks. - Link-local addresses. - Cloud instance metadata services. - IPv6 local, private, or link-local ranges. - Internal DNS names. - Non-HTTP URI schemes accepted by `curl` for the initial URL. - Public URLs that redirect to internal destinations. This creates an SS ...[truncated 1729 chars]
Remediation
View remediation
&2; exit 1 ;; esac ``` 2. Validate the initial URL and every nested playlist, key, segment, and redirect destination. 3. Resolve hostnames and reject destinations in loopback, private, link-local, multicast, unspecified, documentation, and reserved IPv4 and IPv6 ranges. 4. Disable unrestricted redirects or validate every redirect hop. For example, inspect redirect targets before issuing the next request instead of relying on unconditional `curl -L`. 5. Restrict `curl` protocols: ```bash curl --proto '=https' --proto-redir '=https' ... ``` 6. Apply equivalent protocol and destination restrictions to `aria2c`, or download segments through a controlled validation layer. 7. Consider an allowlist of approved media hosts when the expected deployment permits it. 8. Run media downloads in a network sandbox that cannot reach localhost, private networks, metadata services, or other sensitive internal destinations. 9. Set connection, transfer, and file-size limits to reduce denial-of-service exposure from malicious endpoints. ]]>
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Even though it is not deleting /, the skill instructs an agent to execute a forceful recursive deletion command. In an agent context, destructive shell primitives are more dangerous because they may be copied, parameterized, or adapted automatically, and a small path error could delete unrelated files.

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

Step 6: Cleanup

bash
rm -rf /tmp/video_download

Quick Script Usage

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Even though it is not deleting /, the skill instructs an agent to execute a forceful recursive deletion command. In an agent context, destructive shell primitives are more dangerous because they may be copied, parameterized, or adapted automatically, and a small path error could delete unrelated files.

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

Step 6: Cleanup

bash
rm -rf /tmp/video_download

Quick Script Usage

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill contains multiple shell commands (curl, aria2c, ffmpeg, rm -rf) but does not declare any tool scope or allowed-tools metadata. That omission weakens least-privilege controls and makes it easier for an agent to invoke broader shell capabilities than the skill actually needs, increasing the blast radius if the workflow is misused or prompt-injected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The cleanup step uses a recursive force-delete on /tmp/video_download without any warning, validation, or confirmation. Although the path is specific, destructive commands in agent skills are risky because variable substitution, operator error, or later edits can turn routine cleanup into unintended data loss.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.