T08 · Insecure Dependencies
- Location
SKILL.md:168- Finding
Unpinned Third-Party Package Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This video-editing skill is mostly coherent, but it includes an unsafe batch command pattern that can run arbitrary shell commands from a job file.
Review this skill before installing. Use it only on trusted media and trusted working directories, avoid the jobs.txt bash -c batch pattern, and approve any package installation explicitly, preferably inside a virtual environment or container with pinned dependencies.
SKILL.md:168Unpinned Third-Party Package Installation
SKILL.md:362Arbitrary Shell Command Execution Through Batch Job File
The activation description is extremely broad and includes many generic triggers such as any request to edit or process video, plus keyword mentions like 'ffmpeg' or 'moviepy'. This can cause the skill to activate in contexts where a narrower or safer skill should handle the request, increasing the chance of unintended tool use, file processing, or execution of complex media pipelines on unscoped user input.
The Whisper example hard-codes --language pt, which forces Portuguese transcription regardless of the user's media or stated preferences. In practice this can degrade output accuracy, cause incorrect subtitles or transcript-driven edits, and lead the agent to make downstream editing decisions from bad transcript data without user consent.
No suspicious patterns detected.