Back to skill

Security audit

ffmpeg-static

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent FFmpeg helper, but it installs a mutable executable binary package and its examples overwrite output files by default.

Install only if you are comfortable trusting the current npm `ffmpeg-static` release and its downloaded binary. Prefer pinning exact versions, using a lockfile or checksum verification, running media jobs in a low-privilege workspace, and replacing default `-y` examples with explicit overwrite checks or unique output paths.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:11
Finding

Unpinned npm Dependencies Download and Install Executable Binaries

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:11-13, SKILL.md:31, SKILL.md:43-48, templates/node_patterns.txt:3, templates/node_patterns.txt:80
Vulnerability Type: Unpinned third-party dependency and executable binary supply-chain risk
Risk Level: Medium

Vulnerable Code Snippets

SKILL.md:11-13:

yaml
install:
  - kind: npm
    package: ffmpeg-static

SKILL.md:31:

markdown
- `ffmpeg-static` downloads pre-built binaries from GitHub Releases during `npm install`. Verify the package on [npmjs.com/package/ffmpeg-static](https://www.npmjs.com/package/ffmpeg-static).

SKILL.md:43-48:

bash
npm install ffmpeg-static
bash
npm install ffmpeg-static ffprobe-static

templates/node_patterns.txt:3:

text
# Requires: npm install ffmpeg-static ffprobe-static

templates/node_patterns.txt:80:

text
# npm install fluent-ffmpeg

Technical Analysis

The Skill declares and recommends npm dependencies without exact version constraints. In particular, ffmpeg-static performs a binary download during installation, and the downloaded native executable is subsequently resolved for use by the Skill's integration patterns.

Without an exact reviewed version, a committed lockfile with integrity metadata, or independent verification of the downloaded executable, installation trusts the package version currently selected by npm and the external release artifact supplied during its lifecycle. This creates a supply-chain boundary where the effective native executable may differ from the artifact originally audited.

The documentation acknowledges that ffmpeg-static downloads pre-built binaries, but its recommendation to verify the package page does not cryptographically authenticate the installed package or executable. No evidence indicates that the currently referenced packages are malicious; the issue is the unsafe, mutable dependency and ...[truncated 1584 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every npm dependency to an exact reviewed version rather than relying on the latest compatible release.
  2. Commit a lockfile containing npm integrity hashes and use npm ci in automated installation and CI/CD environments.
  3. Verify the downloaded FFmpeg and ffprobe binaries against trusted, version-specific SHA-256 checksums or cryptographic signatures before execution.
  4. Prefer disabling install-time binary downloads and provisioning FFmpeg through a separately authenticated, controlled artifact repository.
  5. Pin ffmpeg-static, ffprobe-static, and optional fluent-ffmpeg versions consistently in all installation examples.
  6. Run package installation and media processing as an unprivileged account in a sandbox or container with restricted filesystem and network access.
  7. Use dependency provenance, registry allowlists, package-manager audit controls, and automated monitoring for package ownership or release changes.
  8. Review lifecycle scripts before installation and, where operationally possible, install with scripts disabled before separately provisioning the verified executable.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description presents this skill as an FFmpeg operations utility for carrying out media-processing tasks. The supplied code does not execute FFmpeg, build pipelines, manipulate streams, extract thumbnails, or convert formats. Its actual function is narrower: locating ffmpeg/ffprobe executables and exposing their paths via module functions or CLI output. This is a materially different primary purpose from the declared operational/media-processing role, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guidance to always pass '-y' causes FFmpeg to overwrite existing output files without confirmation. In automation or when output paths are user-influenced, this can destroy data or clobber important files, and the risk is heightened here because the skill also encourages flexible path and binary selection via environment variables and command construction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file documents the -y flag as overwriting output without prompting and even labels it as required in non-interactive scripts, but it does not include any user-facing warning about potential destruction of existing output files. For markdown files, destructive or irreversible behaviors that may affect user data should be accompanied by a warning.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Most templates include the '-y' flag, which forces overwriting output files without confirmation. In an agent or scripted environment, if output paths are derived from user input or variables, this can cause silent data loss or clobber important files, especially when operators copy-paste commands without noticing the overwrite behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This plain-text template file provides command examples but does not specify any explicit trigger phrases, invocation boundaries, or exclusion conditions for when a related skill should activate. For text and manifest files, missing specificity on trigger scope can cause unintended invocation if the file is used as a skill-facing description or routing source.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.