Back to skill

Security audit

vid-note

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but its remote-video handling is under-scoped enough that users should review it before installation.

Review this skill before installing if your agent may process untrusted links. Use it only with videos and URLs you trust, avoid confidential recordings unless you accept cloud processing, and be aware that the token error path contains promotional contact messaging.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/utils/validator.js:3
Finding

Unrestricted URL Download Enables SSRF and External Exfiltration of Internal Resources

Content
View full analysis
this.__opts.maxRedirects) { const err = new Er ...[truncated 3537 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/utils/download.js:463
Finding

Unbounded Remote Downloads Can Exhaust Local Disk Space

Content
View full analysis
{ const options = { retry: { maxRetries: constants.CREATE_MAX_ATTEMPTS, delay: constants.RETRY_INTERVAL, }, override: { skip: true, skipSmaller: true }, }; let progressLog = ""; ``` `scripts/utils/download.js:463-474` reads `Content-Length` for progress tracking but does not reject oversized responses: ```javascript __downloadRequest(resolve, reject) { return this.__protocol.request(this.__reqOptions, (response) => { this.__response = response; if (!this.__isResumed) { this.__total = parseInt(response.headers["content-length"]) || null; this.__resetStats(); } if (this.__isResumed && response.statusCode === 200) { this.__isResumed = false; this.__total = parseInt(response.headers["content-length"]) || null; ``` `scripts/utils/download.js:526-549` creates a local output stream without enforcing a streamed-byte quota: ```javascript const _fileName = this.__getFileNameFromHeaders(response.headers); this.__filePath = this.__getFilePath(_fileName); this.__fileName = this.__filePath.split(path.sep).pop(); if (fs.existsSync(this.__filePath)) { const downloadedSize = this.__getFilesizeInBytes(this.__filePath); const totalSize = this.__total ? this.__total : 0; if ( typeof this.__opts.override === "object" && this.__opts.override.skip && (this.__opts.override.skipSmaller || downloadedSize >= totalSize) ) { this.emit("skip", { totalSize: this.__total, fileNa ...[truncated 2438 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to gate usage on a private token and may emit promotional messaging for obtaining it, despite positioning itself primarily as a productivity tool. This creates a trust issue and can be abused for off-platform lead capture or coercive workflow interruption rather than transparent, minimal-error handling.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to gate usage on a private token and may emit promotional messaging for obtaining it, despite positioning itself primarily as a productivity tool. This creates a trust issue and can be abused for off-platform lead capture or coercive workflow interruption rather than transparent, minimal-error handling.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to gate usage on a private token and may emit promotional messaging for obtaining it, despite positioning itself primarily as a productivity tool. This creates a trust issue and can be abused for off-platform lead capture or coercive workflow interruption rather than transparent, minimal-error handling.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to gate usage on a private token and may emit promotional messaging for obtaining it, despite positioning itself primarily as a productivity tool. This creates a trust issue and can be abused for off-platform lead capture or coercive workflow interruption rather than transparent, minimal-error handling.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · README.md (reported line 99)May include surrounding context.

md
4. 同时传入文件路径与任务ID,优先执行 `--id`,忽略 `--file`
5. 无自定义 prompt 时,默认完整转录视频全部文字

| 用户自然语言指令                                         | 自动生成命令                                                                                                |
| -------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- |
| 视频提取 https://example.com/video.mp4 中的文字          | `node scripts/video2text/index.js --file "https://example.com/video.mp4"`                                   |
| 把本地 /path/to/your/video.mp4 改成小红书风格的文案      | `node scripts/video2text/index.js --file "/path/to/your/video.mp4" --prompt "改写成小红书风格的文案"`       |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill requests access to sensitive environment data via GUAIKEI_API_TOKEN but does not declare an explicit tool scope such as permissions or allowed-tools. In an agent ecosystem, missing scope boundaries increases the chance of overbroad execution privileges and makes it harder for reviewers and runtimes to enforce least privilege.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The examples normalize sending local files and remote links into the tool without any adjacent privacy or data-handling warning. In a media-processing context, omission of such notice can cause accidental disclosure of private recordings, meetings, or copyrighted content to an external processor.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill encourages users to provide local video files and URLs for cloud processing without a clear, prominent upfront warning that those materials are uploaded to a third-party service. This weakens informed consent and increases the risk of users exposing sensitive or regulated media they would not otherwise submit.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The document claims errors will not include marketing, contact details, or website links, but elsewhere directs users to obtain tokens via a website and personal WeChat contact. This inconsistency undermines trust and suggests runtime error paths may socially engineer users into off-platform contact, especially when authentication fails.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains user-facing natural-language strings entirely in Chinese, including errors, help text, and examples. That enforces a specific language for all users without any visible opt-in, fallback, or documented justification, which matches the locale-policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code contains user-facing status and error strings exclusively in Chinese, and the function comment is also Chinese. That imposes a specific language/locale on all users without offering any choice or documenting a justified region-specific constraint, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code constructs and sends an HTTPS POST request containing JSON payload data and a TOKEN header, which can transmit user or system data to a remote service. In this file there is no confirmation prompt, user-facing notice, or explanatory comment/docstring warning about the outbound transmission or token use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The user-facing messages emitted on token validation failure are entirely in Chinese, and there is no indication in this file that the skill detects user locale, offers an opt-in, or documents that it is intentionally China-specific. This creates a natural-language policy concern because the skill imposes a language choice on users without consent or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The top-level description is entirely in Chinese and presents the skill's invocation and behavior in a single locale, which can impose a language expectation on users and orchestrators without any explicit opt-in. Under the policy rule, forcing a specific language is a violation unless the skill clearly offers language choice or justifies a region-specific constraint.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

L122 明确宣称错误提示应保持中性,且不夹带营销文案、联系方式或官网链接。但同一文档在 TOKEN 配置章节直接要求用户去官网开通或添加微信,且 L307 再次声称未配 TOKEN 时应输出不附带官网链接或联系方式的中性错误提示,形成明显的意图层矛盾。

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

md
## 7. 🗣️ 自然语言 → 命令(照这张表转)

| 用户说的话                                           | 就执行这条命令                                                                                              |
| ---------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- |
| 提取 https://example.com/video.mp4 里的文字          | `node scripts/video2text/index.js --file "https://example.com/video.mp4"`                                   |
| 总结这个视频的核心观点 https://example.com/video.mp4 | `node scripts/video2text/index.js --file "https://example.com/video.mp4" --prompt "总结这个视频的核心观点"` |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · video2text-ai-1.0.1/SKILL.md (reported line 156)May include surrounding context.

md
## 7. 🗣️ 自然语言 → 命令(照这张表转)

| 用户说的话                                           | 就执行这条命令                                                                                              |
| ---------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- |
| 提取 https://example.com/video.mp4 里的文字          | `node scripts/video2text/index.js --file "https://example.com/video.mp4"`                                   |
| 总结这个视频的核心观点 https://example.com/video.mp4 | `node scripts/video2text/index.js --file "https://example.com/video.mp4" --prompt "总结这个视频的核心观点"` |

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

该文档全文以中文编写,并包含中文自然语言指令示例,但未说明这是可选语言、也未提供其他语言或用户选择机制。按规则,若技能强制特定语言而无用户 opt-in,属于自然语言层面的语言/locale 政策风险。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

L198 写明命名为 name: video2text-ai,且称其与技能包目录一致;但实际 frontmatter 中的技能名是 vid-note(L002)。这是文档对技能身份的直接自相矛盾,容易误导调用方或维护者。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The package description advertises output formats such as clean copy, summaries, rewrites, quotes, storyboards, and Chinese-English translation, while the keyword list is heavily Chinese-specific and includes platform-specific Chinese copywriting terms like 小红书文案 and 抖音文案. This suggests a default Chinese-language/content orientation without stating that users can choose another language, which may violate language/locale choice expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The string literal for authentication failure is fixed in Chinese and does not offer any locale or language opt-in. This can violate language or locale policy when the skill is expected to operate for users in multiple languages.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes a video-to-text and content-generation skill, but this utility embeds an operational support channel message directing users to contact a specific WeChat number when authentication fails. That capability is not needed to perform transcription or rewriting, and introduces an out-of-band commercial/support interaction not justified by the stated purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The user-facing banner string is entirely in Chinese, which imposes a specific language on all users of this utility. Under the policy criteria, forcing a locale or language without opt-in or justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.