Back to skill

Security audit

mp3-list-to-video

Security checks for vulnerabilities and agentic risk

Overview

This skill locally combines MP3 files into MP4 playlist videos and does not show hidden, persistent, network, credential, or destructive behavior.

Use this skill only on media files you intend to process, and choose output/temp paths carefully because ffmpeg may overwrite existing files. Expect local CPU/disk use and local timeline files containing playlist filenames; no network or credential access was found.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill advertises substantially richer behavior than the analysis indicates is actually implemented. This kind of description-behavior mismatch is dangerous because users or orchestration layers may trust the declared capabilities, skip validation, or make decisions based on nonexistent checks and rendering steps, which can lead to unsafe automation assumptions and incorrect execution paths.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill instructs the agent to run shell commands and write files, but it does not declare any explicit tool scope such as allowed-tools or permissions. That makes the skill's operational boundary ambiguous and can let an agent invoke broader shell/file capabilities than reviewers or users expect, increasing the chance of unintended command execution or filesystem modification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description and usage guidance are written entirely in Chinese, and the trigger list mixes Chinese and English without stating that language choice is optional. For a general-purpose media-processing skill, this creates an implicit language/locale constraint without documenting user choice or a region-specific justification.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 374)May include surrounding context.

brew install ffmpeg

Ubuntu/Debian

sudo apt install ffmpeg

text

### 输出视频时长为 0

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/add_playlist_menu.py (reported line 62)May include surrounding context.

python
def run_command(cmd, label, cwd=None):
    try:
        return subprocess.run(cmd, check=True, capture_output=True, text=True, cwd=cwd)
    except FileNotFoundError as exc:
        raise RuntimeError(f"{label} 未找到: {cmd[0]}") from exc
    except subprocess.CalledProcessError as exc:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/merge_playlist.py (reported line 44)May include surrounding context.

python
def run_command(cmd, label):
    try:
        return subprocess.run(cmd, check=True, capture_output=True, text=True)
    except FileNotFoundError as exc:
        raise RuntimeError(f"{label} 未找到: {cmd[0]}") from exc
    except subprocess.CalledProcessError as exc:

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file contains user-facing docstrings, status messages, errors, and argument help text entirely in Chinese, which imposes a specific language on users. Under the stated policy, forcing a language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified or configurable.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language strings entirely in Chinese, including the module docstring, runtime messages, and CLI help text. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.