Back to skill

Security audit

listenvideo

Security checks for vulnerabilities and agentic risk

Overview

This skill does a plausible video-to-text job, but it under-discloses where sensitive video data and downloaded URL content may go.

Install only if you are comfortable sending selected videos, prompts, token-authenticated requests, and possibly local path metadata to this vendor's cloud workflow. Avoid processing confidential media or attacker-supplied URLs until the skill restricts URL downloads, validates redirects, limits file size/time, and documents/allowlists upload destinations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/utils/validator.js:3
Finding

Server-Side Request Forgery Through Unrestricted Video URLs and Redirects

Content
View full analysis
{ if (this.__isRequireRedirect(response)) { redirectCount++; if (redirectCount > this.__opts.maxRedirects) { const err = new Error("Too many redirects"); this.__setState(this.__states.FAILED); this.emit("error", err); return reject(err); } const redirectedURL = /^https?:\/\//.test(response.headers.locatio ...[truncated 2382 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/utils/helper.js:26
Finding

Unbounded Remote Downloads Can Exhaust Local Storage

Content
View full analysis
{ const options = { retry: { maxRetries: constants.CREATE_MAX_ATTEMPTS, delay: constants.RETRY_INTERVAL, }, override: { skip: true, skipSmaller: true }, }; ``` ```js // scripts/utils/download.js:35-50 this.__defaultOpts = { body: null, retry: false, method: "GET", headers: {}, fileName: "", timeout: -1, metadata: null, override: false, forceResume: false, removeOnStop: true, removeOnFail: true, maxRedirects: 10, progressThrottle: 1000, httpRequestOptions: {}, httpsRequestOptions: {}, resumeOnIncomplete: true, ``` ### Technical Analysis The remote download configuration does not impose a maximum response size or streaming byte limit. It also inherits a downloader default timeout of `-1`, with no total-operation deadline configured by the wrapper. A remote server can omit `Content-Length`, report a misleading value, use chunked transfer encoding, or serve an extremely large object. The implementation continues writing received data to the project’s `tmp` directory without enforcing an application-level quota. The retry behavior can further increase resource consumption when a hostile or unstable server repeatedly interrupts transfers. ### Attack Path 1. An attacker provides a URL controlled by the attacker. 2. The server returns an oversized response or an indefinite chunked stream. 3. The downloader writes the response to the local temporary directory. 4. No maximum byte count is checked while streaming. 5. The transfer continues until the remote server closes the connection, the process is terminated, or local storage is exhausted. 6. Exha ...[truncated 642 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/utils/upload.js:11
Finding

Local Video Upload Destination Is Controlled by an Unvalidated API Response

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/api/video.js:11
Finding

Full Local Filesystem Path Is Disclosed to the Remote API

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill documentation includes token-gating and promotional contact flows while asserting neutral error handling and a narrowly defined transcription purpose. Misrepresentation of behavior and error UX can mislead users about what the skill does, what data is sent off-box, and whether failures expose marketing or tracking content, which weakens informed consent and trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill documentation includes token-gating and promotional contact flows while asserting neutral error handling and a narrowly defined transcription purpose. Misrepresentation of behavior and error UX can mislead users about what the skill does, what data is sent off-box, and whether failures expose marketing or tracking content, which weakens informed consent and trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill documentation includes token-gating and promotional contact flows while asserting neutral error handling and a narrowly defined transcription purpose. Misrepresentation of behavior and error UX can mislead users about what the skill does, what data is sent off-box, and whether failures expose marketing or tracking content, which weakens informed consent and trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documentation includes token-gating and promotional contact flows while asserting neutral error handling and a narrowly defined transcription purpose. Misrepresentation of behavior and error UX can mislead users about what the skill does, what data is sent off-box, and whether failures expose marketing or tracking content, which weakens informed consent and trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill documentation includes token-gating and promotional contact flows while asserting neutral error handling and a narrowly defined transcription purpose. Misrepresentation of behavior and error UX can mislead users about what the skill does, what data is sent off-box, and whether failures expose marketing or tracking content, which weakens informed consent and trust.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

文件标题与全文内容均以中文呈现,且未说明该技能仅面向特定中文用户群,也未提供其他语言选项或用户选择机制。根据规则,强制特定语言而无用户 opt-in 属于自然语言层面的语言/locale policy violation。

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · README.md (reported line 99)May include surrounding context.

md
4. 同时传入文件路径与任务ID,优先执行 `--id`,忽略 `--file`
5. 无自定义 prompt 时,默认完整转录视频全部文字

| 用户自然语言指令                                         | 自动生成命令                                                                                                |
| -------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- |
| 视频提取 https://example.com/video.mp4 中的文字          | `node scripts/video2text/index.js --file "https://example.com/video.mp4"`                                   |
| 把本地 /path/to/your/video.mp4 改成小红书风格的文案      | `node scripts/video2text/index.js --file "/path/to/your/video.mp4" --prompt "改写成小红书风格的文案"`       |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill requests access to an environment secret (GUAIKEI_API_TOKEN) but does not declare an explicit tool scope such as permissions or allowed-tools. In an agent environment, missing scope declarations reduce transparency and can let a skill obtain sensitive capabilities without clear policy review, especially when the same document also instructs remote upload of user-provided content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill processes user-supplied videos through a remote cloud service, but the top-level description does not prominently warn that links or files may be uploaded off-device for processing. For privacy-sensitive media, lack of clear upfront disclosure prevents informed consent and can expose confidential audio/video content to an external processor unexpectedly.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trust section says the skill only talks to guaikei.com, but the rest of the skill says it accepts arbitrary public video URLs from many platforms and downloads them before upload. This contradiction obscures the real network and privacy boundary, which is dangerous because users may believe only one trusted domain is contacted when the workflow necessarily interacts with third-party sources.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document promises neutral errors without marketing or contact information, yet elsewhere embeds website and WeChat contact details in setup and support guidance. This inconsistency can be used to socially engineer users during failure states and undermines trust claims made in the security section.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JavaScript file contains natural-language user-facing strings exclusively in Chinese, beginning with the file-level description and continuing through error/help text. Under the policy, forcing a specific language without user opt-in or a documented locale-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The downloader is configured by default to delete files when a download is stopped or fails, and the implementation later unlinks the target file in stop and error paths. While events are emitted for programmatic consumers, there is no direct user-facing warning, confirmation prompt, or explanatory comment in this file alerting users that partial downloads may be removed automatically.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code emits user-facing natural-language error text in Chinese, which imposes a specific language on users without offering a language choice or documenting a justified locale restriction. The same pattern appears throughout the file, indicating a language policy issue rather than an isolated internal string.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill emits all user-facing status and promotional text exclusively in Chinese, including warnings and recovery instructions. This creates a language/locale policy concern because users are not offered any language choice or opt-in, and the file does not document a justified region-specific restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The banner text is hard-coded in Chinese ("视频文案智能提取助手"), which imposes a specific language on users. The file does not provide any opt-in, fallback, or documented justification for this locale restriction, matching the policy's language/locale violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code presents command descriptions, examples, and operational messages in Chinese only, which imposes a specific language on users without opt-in. The policy for this audit flags forced language or locale behavior unless the skill offers a choice or clearly documents a justified regional scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The primary description is written as a blanket Chinese-only invocation and usage description, with no opt-in or explicit language choice for users. This creates a locale/language policy concern because the skill presents itself as requiring or defaulting to a specific language rather than offering a user-selectable language.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

md
## 7. 🗣️ 自然语言 → 命令(照这张表转)

| 用户说的话                                           | 就执行这条命令                                                                                              |
| ---------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- |
| 提取 https://example.com/video.mp4 里的文字          | `node scripts/video2text/index.js --file "https://example.com/video.mp4"`                                   |
| 总结这个视频的核心观点 https://example.com/video.mp4 | `node scripts/video2text/index.js --file "https://example.com/video.mp4" --prompt "总结这个视频的核心观点"` |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · video2text-ai-1.0.1/SKILL.md (reported line 156)May include surrounding context.

md
## 7. 🗣️ 自然语言 → 命令(照这张表转)

| 用户说的话                                           | 就执行这条命令                                                                                              |
| ---------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- |
| 提取 https://example.com/video.mp4 里的文字          | `node scripts/video2text/index.js --file "https://example.com/video.mp4"`                                   |
| 总结这个视频的核心观点 https://example.com/video.mp4 | `node scripts/video2text/index.js --file "https://example.com/video.mp4" --prompt "总结这个视频的核心观点"` |

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The description and trigger guidance prescribe Chinese trigger phrases and user interaction patterns without stating that other languages are supported for invocation. Under the locale policy, forcing a specific language without user opt-in can be a natural-language policy issue unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JavaScript file uses Chinese-only natural-language strings in comments, operation labels, and thrown error messages throughout the module. Under the policy, forcing a specific language without user choice or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This file hardcodes user-facing/logging language in Chinese, and the docstring/commentary indicate the skill is written for a fixed locale without offering any language choice. The policy for this review flags language or locale constraints when they are imposed without explicit opt-in or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.