Back to skill

Security audit

Video Editor

Security checks for vulnerabilities and agentic risk

Overview

This video-editing skill is mostly coherent, but it includes an unsafe batch command pattern that can run arbitrary shell commands from a job file.

Review this skill before installing. Use it only on trusted media and trusted working directories, avoid the jobs.txt bash -c batch pattern, and approve any package installation explicitly, preferably inside a virtual environment or container with pinned dependencies.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:168
Finding

Unpinned Third-Party Package Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:362
Finding

Arbitrary Shell Command Execution Through Batch Job File

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation description is extremely broad and includes many generic triggers such as any request to edit or process video, plus keyword mentions like 'ffmpeg' or 'moviepy'. This can cause the skill to activate in contexts where a narrower or safer skill should handle the request, increasing the chance of unintended tool use, file processing, or execution of complex media pipelines on unscoped user input.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The Whisper example hard-codes --language pt, which forces Portuguese transcription regardless of the user's media or stated preferences. In practice this can degrade output accuracy, cause incorrect subtitles or transcript-driven edits, and lead the agent to make downstream editing decisions from bad transcript data without user consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.