Back to skill

Security audit

Quickscribe

Security checks for vulnerabilities and agentic risk

Overview

This video transcription skill is mostly purpose-aligned, but it accepts arbitrary URLs and can download then upload unexpected internal or oversized content to a remote service.

Install only if users understand that selected local videos, downloaded URL content, prompts, task IDs, the API token, and some file metadata are sent to a third-party service. Avoid confidential, regulated, internal-network, localhost, metadata-service, or untrusted URLs unless the skill is first constrained with URL allowlists, private-address blocking, media validation, and size limits.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/utils/validator.js:3
Finding

Unrestricted URL Downloads Enable SSRF and Internal Resource Exfiltration

Content
View full analysis
{ if (this.__isRequireRedirect(response)) { redirectCount++; if (redirectCount > this.__opts.maxRedirects) { const err = new Error("Too many redirects"); this.__setState(this.__states.FAILED); this.emit("error", err); return reject(err); } const redirectedURL = /^https?:\/\//.test(response.headers.location) ? response.headers.location : new URL(response.headers.location, url).href; this.emit("redirected", redirectedURL, url); return getRequest(redirectedURL, getReqOptions(redirectedURL)); ``` ### Technical Analysis URL validation verifies only that the supplied scheme is HTTP or HTTPS. It does not reject: - Loopback addresses such as `127.0.0.1` and `::1` - Private network ranges - Link-local addresses such as `169.254.0.0/16` - Cloud metadata endpoints - IPv4 addresses encoded in alternative formats - Hostnames that resolve to private or reserved addresses - DNS rebinding - Redirects from public hosts to internal ...[truncated 2168 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/utils/helper.js:27
Finding

Unbounded Remote Downloads Can Exhaust Disk and Network Resources

Content
View full analysis
{ const options = { retry: { maxRetries: constants.CREATE_MAX_ATTEMPTS, delay: constants.RETRY_INTERVAL, }, override: { skip: true, skipSmaller: true }, }; ``` `scripts/utils/download.js:344-347` ```js resolve({ name: this.__getFileNameFromHeaders(response.headers, response), total: parseInt(response.headers["content-length"]) || null, }); ``` `scripts/utils/download.js:547-549` ```js this.__fileStream = fs.createWriteStream(this.__filePath, {}); } else { this.__fileStream = fs.createWriteStream(this.__filePath, { flags: "a" }); ``` ### Technical Analysis The downloader reads the remote `Content-Length` value but does not enforce a maximum permitted size. It also accepts responses without a `Content-Length` header and streams their bodies directly to disk. No maximum-byte option is supplied by `helper.download()`. Consequently, a server can return a very large object or a long-lived chunked response. The file continues to grow until the transfer finishes, an error occurs, the process is terminated, or available storage is exhausted. Configured retries can increase bandwidth and execution time after failures. Temporary cleanup does not prevent the issue because it removes only entries older than 24 hours and runs at invocation time; it does not enforce a quota during an active download. ### Attack Path 1. An attacker supplies a URL controlled by the attacker or pointing to an extremely large resource. 2. The remote server declares a very large `Content-Length`, omits the header, or sends an extended chunked response. 3. The Skill op ...[truncated 1062 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/api/video.js:11
Finding

Absolute Local File Paths Are Disclosed to the Remote API

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (22)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises cloud processing and privacy protections, but the description in the flagged area does not prominently warn users that supplying a file path or video URL results in content being sent to a remote service. This can mislead users into exposing sensitive local or linked video content under the assumption of local-only processing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README defines broad natural-language-to-command conversion rules and examples that could cause ordinary user phrasing to be treated as an activation request without clear boundaries or confirmation. In an agent setting, this can lead to unintended processing of local files or remote URLs, including uploading user-provided media to a third-party service.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · README.md (reported line 99)May include surrounding context.

md
4. 同时传入文件路径与任务ID,优先执行 `--id`,忽略 `--file`
5. 无自定义 prompt 时,默认完整转录视频全部文字

| 用户自然语言指令                                         | 自动生成命令                                                                                                |
| -------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- |
| 视频提取 https://example.com/video.mp4 中的文字          | `node scripts/video2text/index.js --file "https://example.com/video.mp4"`                                   |
| 把本地 /path/to/your/video.mp4 改成小红书风格的文案      | `node scripts/video2text/index.js --file "/path/to/your/video.mp4" --prompt "改写成小红书风格的文案"`       |

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description is entirely in Chinese and presents the skill as operating in Chinese-specific content contexts, but it does not state that this is a Chinese-only skill or offer any language/locale opt-in. Under the policy, forcing a specific language without user choice can be a natural-language policy violation unless clearly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs users to upload local files or public video URLs to a third-party cloud service, which creates a real data exposure risk if users submit sensitive recordings. Although the document includes later privacy assurances, the transfer/privacy warning is not prominent at the point of use, increasing the chance of inadvertent disclosure of confidential audio/video content.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description is extremely broad, covering many common content-creation and transcription scenarios without clear limits on when the skill should be invoked. In agent ecosystems, this can cause over-selection or unintended activation for unrelated user requests, increasing the chance that local files, external links, or sensitive media are processed by this skill without strong user intent verification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

All user-facing metadata is written in Chinese with no declared locale scope or language-selection guidance. In multi-language agent environments, this can lead to incorrect routing, user misunderstanding, or consent issues if non-Chinese-speaking users trigger the skill without understanding that it accepts links/files for external processing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This utility emits natural-language error and help strings exclusively in Chinese, including comments, thrown errors, and generated usage text. Because the file does not indicate that the skill is China-specific or provide any opt-in/selection for locale, it appears to force a specific language, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The stop path deletes the target file with fs.unlink when removeOnStop is enabled, and the failure path can also remove files when removeOnFail is enabled, yet there is no user-facing warning or confirmation around this destructive behavior. Silent deletion is safety-relevant because it can remove partially downloaded or existing output files without explicit disclosure at the point of action.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code performs HTTP/HTTPS requests to remote URLs and writes the response directly to disk, but the file contains no confirmation prompt, user-facing log/print, or explanatory comment/docstring warning about those safety-relevant actions. Because it both transfers remote data and creates local files, users invoking the skill may not receive any visible notice that these operations will occur.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JavaScript file contains natural-language comments and runtime status/error messages exclusively in Chinese, such as the docstring at L25-L26 and multiple inlineLog messages from L41 onward. That enforces a specific language for users without offering a locale choice or documenting a justified regional constraint, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Several error strings are presented only in Chinese, including token failure and request/parsing errors. This forces a specific language/locale for user-visible communication without offering a choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The user-facing strings in this file are exclusively in Chinese, including warnings and guidance shown when token validation fails. This creates a language/locale policy issue because the skill does not provide user opt-in, fallback language handling, or any indication that it is intentionally limited to a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The comment states a strong behavioral/privacy guarantee: uploaded videos will not be leaked, stored elsewhere, or used for other purposes, and will be automatically deleted after transcription. The implementation only validates HTTPS and uploads a file to a caller-supplied presigned URL; it contains no code to verify post-upload handling, restrict downstream use, or delete the uploaded content after processing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file contains natural-language instructions and runtime messages exclusively in Chinese, including the function documentation and error text. Under the stated policy, forcing a specific language without user opt-in is a locale-policy issue unless the skill documents that it is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The user-facing flag descriptions, help text, and examples are all presented only in Chinese. This imposes a specific language on users without any visible opt-in or justification for a region-specific audience, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

L119 claims the skill 'only' communicates with https://www.guaikei.com and sends no other requests. But the skill's documented operation explicitly supports fetching videos from arbitrary public URLs such as Douyin, Xiaohongshu, Bilibili, Weibo, and generic example.com links (e.g. L55-L58, L135, L187), which necessarily entails network communication with non-guaikei hosts.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Lines L122-L123 state that error prompts should be neutral and should not include marketing copy, contact details, or website links. However, nearby operational guidance directs users to obtain tokens via the official website and WeChat contact (for example L103 and L331-L333), creating an active contradiction in the documented intent around user-facing error/support messaging.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

md
## 7. 🗣️ 自然语言 → 命令(照这张表转)

| 用户说的话                                           | 就执行这条命令                                                                                              |
| ---------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- |
| 提取 https://example.com/video.mp4 里的文字          | `node scripts/video2text/index.js --file "https://example.com/video.mp4"`                                   |
| 总结这个视频的核心观点 https://example.com/video.mp4 | `node scripts/video2text/index.js --file "https://example.com/video.mp4" --prompt "总结这个视频的核心观点"` |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · video2text-ai-1.0.1/SKILL.md (reported line 156)May include surrounding context.

md
## 7. 🗣️ 自然语言 → 命令(照这张表转)

| 用户说的话                                           | 就执行这条命令                                                                                              |
| ---------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- |
| 提取 https://example.com/video.mp4 里的文字          | `node scripts/video2text/index.js --file "https://example.com/video.mp4"`                                   |
| 总结这个视频的核心观点 https://example.com/video.mp4 | `node scripts/video2text/index.js --file "https://example.com/video.mp4" --prompt "总结这个视频的核心观点"` |

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This code constructs and sends an HTTPS POST request containing a TOKEN header and JSON payload, which may include user or system data. In this file there is no confirmation prompt, user-facing notice, or explanatory comment/docstring disclosing that outbound network transmission and credential use will occur.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The banner text is hard-coded in Chinese, which imposes a specific language in user-facing output. The file does not offer any locale selection, fallback, or documented justification for restricting output to Chinese.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.