Back to skill

Security audit

爆款短视频拆解

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly purpose-aligned, but its transcription workflow can automatically install and run unverified native dependencies from third-party or mutable sources.

Install only if you are comfortable with the skill downloading and installing transcription dependencies. Prefer running setup manually in an isolated virtual environment, verify FFmpeg from an official source with a pinned checksum, avoid the gh-proxy path unless you explicitly trust it, and review any generated scripts for copyright, platform-policy, medical, or financial claims before publishing.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
scripts/setup_transcribe.py:32
Finding

Unverified FFmpeg Binary Automatically Downloaded Through a Third-Party Proxy and Executed

Content
View full analysis

Vulnerability Details

File Location: scripts/setup_transcribe.py:32-33, 92-112, 144; reachable automatically through scripts/transcribe.py:57-68
Vulnerability Type: Unsafe dependency retrieval and native binary execution
Risk Level: High

Complete Code Snippet

python
# scripts/setup_transcribe.py:32-33
GH_PROXY = "https://gh-proxy.com/https://github.com"
OFFICIAL = "https://github.com"
python
# scripts/setup_transcribe.py:92-112
fname, kind = ASSETS[sys.platform]
archive = os.path.join(FF_DIR, fname)
ok = False
for base in (GH_PROXY, OFFICIAL):
    url = f"{base}/BtbN/FFmpeg-Builds/releases/download/latest/{fname}"
    try:
        download(url, archive)
        ok = True
        break
    except Exception as e:
        log(f"Mirror source failed, trying the next one: {e}")
if not ok:
    die("ffmpeg download failed")

extract(archive, kind, FF_DIR)
os.remove(archive)
exe = find_ffmpeg_exe(FF_DIR)
if not exe:
    die(f"ffmpeg executable not found after extraction: {FF_DIR}")
with open(MARKER, "w", encoding="utf-8") as f:
    f.write(exe)
python
# scripts/setup_transcribe.py:144
rc = subprocess.run([ff_exe, "-version"], capture_output=True, text=True)
python
# scripts/transcribe.py:57-68
def ensure_ready():
    if deps_ready():
        return load_ffmpeg()
    print("[transcribe] dependencies unavailable; automatically running installer")
    setup = os.path.join(
        os.path.dirname(os.path.abspath(__file__)),
        "setup_transcribe.py"
    )
    rc = subprocess.run([sys.executable, setup])
    if rc.returncode != 0:
        sys.exit("automatic installation failed")
    if not deps_ready():
        sys.exit("dependencies remain unavailable after installation")
    return load_ffmpeg()

Technical Analysis

When transcription dependencies are missing, transcribe.py automatically invokes setup_transcribe.py. The installer preferentially downloads a mutable latest FFmpeg archive through `gh-pro ...[truncated 2179 chars]

Remediation
View remediation

Remediation Suggestions

  1. Download release artifacts directly from the upstream publisher by default.
  2. Pin FFmpeg to an immutable version instead of the mutable latest path.
  3. Maintain a trusted SHA-256 digest for each supported operating-system artifact and verify it before extraction.
  4. Prefer verification of a trusted publisher signature where upstream signatures are available.
  5. Delete the archive and abort installation on any checksum, signature, filename, or platform mismatch.
  6. Do not execute the downloaded binary as a verification mechanism until its authenticity has been established.
  7. Remove the third-party proxy or require the user to explicitly opt into it after disclosing that it becomes part of the executable-code trust chain.
  8. If a proxy must remain supported, verify the downloaded bytes against a digest obtained through an independent trusted channel.
  9. Consider requiring explicit confirmation before automatic dependency installation so users can review the source, version, and expected digest.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向短视频内容理解与生成的完整生产线,而实际代码只是一个依赖安装器,主要负责配置 ffmpeg 和 openai-whisper 以支持后续转录流程。虽然声明中提到“内含视频转文字流程”,该脚本可被视为该流程的准备步骤,但它本身并未执行转录,更未实现描述中的核心能力。代码的主要目的与声明的主要用途存在实质性差异,因此应判定为不匹配。

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/sensitive_check.py (reported line 28)May include surrounding context.

python
rules = []
    safe_cont = {}
    if not os.path.exists(path):
        return rules, safe_cont
    with open(path, "r", encoding="utf-8") as f:
        for raw in f:
            line = raw.rstrip("\n")

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/sensitive_check.py (reported line 49)May include surrounding context.

python
rules = []
    safe_cont = {}
    if not os.path.exists(path):
        return rules, safe_cont
    with open(path, "r", encoding="utf-8") as f:
        for raw in f:
            line = raw.rstrip("\n")

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill references scripts that perform transcription setup and execution, including shell execution, network downloads, environment manipulation, and file writes, but it declares no explicit tool scope or permissions. This creates an overprivileged and opaque execution surface where an agent may invoke powerful capabilities without clear user/admin review, increasing the risk of unintended command execution or dependency installation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Overly broad trigger phrases can cause the skill to activate in conversations that only casually mention short-video topics, links, or scripting. In this skill, accidental activation is more concerning because downstream behavior includes references to local file processing, transcription setup, and potentially networked dependency installation, so a routing mistake could expose unnecessary capabilities or produce unsafe content transformations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

全文技能说明与输出约束均默认中文语境,覆盖 YouTube 等多平台场景时也未说明可根据用户偏好切换语言或地区。若技能在多语言环境中被调用,这种默认单一语言策略可能构成语言/locale 方面的自然语言政策问题。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger list includes many generic phrases such as asking for a script, analysis, or whether content will be rate-limited, without sufficient disambiguation. Because the skill can steer the agent into content rewriting, prompt reverse-engineering, and operational steps for transcription/compliance, broad matching increases the chance of unintended invocation and misuse in contexts not meant for this workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

Lines L33-L34 prescribe fixed Chinese disclaimer and declaration text to append to outputs, but the file does not indicate that language should match the user's preferred locale or that this is limited to a Chinese-only workflow. That creates a natural-language locale policy concern because the skill appears to force a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document title and HTML template hard-code Chinese output, including lang="zh-CN" and Chinese report headings, which indicates the skill is designed to produce output only in Chinese. The policy allows locale constraints only when user choice or clear justification is provided, neither of which appears in this file.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file flags engagement-bait as non-compliant for some platforms, yet the B站 section still recommends the stock phrase “一键三连” as standard copy. In a skill explicitly designed to mass-produce viral video scripts and help users avoid throttling, this creates contradictory guidance that can operationalize platform-gaming behavior and increase the chance users generate manipulative or policy-violating calls to action.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module docstring is entirely in Chinese and serves as the primary user-facing usage and behavior documentation for this setup script. The file does not offer an alternative language, opt-in, or any justification that the skill is intended only for a Chinese-speaking or region-specific environment, which is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

User-visible logs and completion guidance such as download/extract/install messages are emitted exclusively in Chinese. Because the script does not offer language selection or document a justified locale restriction, it forces a specific language during operation.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/setup_transcribe.py (reported line 131)May include surrounding context.

python
except Exception:
        pass
    log("pip 安装 openai-whisper(含 torch CPU,体积较大,请耐心等待)...")
    rc = subprocess.run([py, "-m", "pip", "install", "--upgrade", "pip"],
                        capture_output=True, text=True)
    if rc.returncode != 0:
        log(f"pip upgrade 警告(不影响后续): {rc.stderr[-300:]}")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
87% confidence
Finding

The script performs an unpinned pip install openai-whisper at runtime, pulling code and transitive dependencies from external package indexes into the active interpreter. This creates a supply-chain exposure: if the package, dependency resolution path, or index configuration is compromised, arbitrary code could be installed and later executed in the user's environment.

Content

Scanner excerpt · scripts/setup_transcribe.py (reported line 135)May include surrounding context.

python
capture_output=True, text=True)
    if rc.returncode != 0:
        log(f"pip upgrade 警告(不影响后续): {rc.stderr[-300:]}")
    rc = subprocess.run([py, "-m", "pip", "install", "openai-whisper"],
                        capture_output=True, text=True)
    if rc.returncode != 0:
        die(f"openai-whisper 安装失败:\n{rc.stderr[-800:]}")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/setup_transcribe.py (reported line 144)May include surrounding context.

python
def verify(ff_exe):
    log("自检开始 ---")
    # ffmpeg
    rc = subprocess.run([ff_exe, "-version"], capture_output=True, text=True)
    if rc.returncode != 0:
        die(f"ffmpeg 自检失败: {rc.stderr[-300:]}")
    log("ffmpeg -version OK: " + rc.stdout.splitlines()[0])

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/setup_transcribe.py (reported line 149)May include surrounding context.

python
die(f"ffmpeg 自检失败: {rc.stderr[-300:]}")
    log("ffmpeg -version OK: " + rc.stdout.splitlines()[0])
    # whisper
    rc = subprocess.run([sys.executable, "-c", "import whisper; print('whisper', whisper.__version__ if hasattr(whisper,'__version__') else 'ok')"],
                        capture_output=True, text=True)
    if rc.returncode != 0:
        die(f"whisper 自检失败: {rc.stderr[-300:]}")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/transcribe.py (reported line 51)May include surrounding context.

python
exe = f.read().strip()
    if not os.path.exists(exe):
        return False
    rc = subprocess.run([sys.executable, "-c", "import whisper"],
                        capture_output=True, text=True)
    return rc.returncode == 0

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Auto-installing dependencies by executing a setup script is a real security concern because it turns a transcription operation into an installation-and-execution workflow. In a skill that processes user-supplied media and is expected to be easy to run, this behavior makes accidental execution of unreviewed installer logic more likely and increases exposure to supply-chain attacks or malicious modification of the setup script.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
79% confidence
Finding

The script automatically executes a sibling setup script when dependencies are missing, which creates an implicit code-execution path during normal use. If the repository or local files are tampered with, running transcribe.py will execute setup_transcribe.py without an explicit user confirmation step, increasing the blast radius of supply-chain or local-file compromise.

Content

Scanner excerpt · scripts/transcribe.py (reported line 65)May include surrounding context.

python
return load_ffmpeg()
    print("[transcribe] 依赖未就绪,自动运行安装器 scripts/setup_transcribe.py ...")
    setup = os.path.join(os.path.dirname(os.path.abspath(__file__)), "setup_transcribe.py")
    rc = subprocess.run([sys.executable, setup])
    if rc.returncode != 0:
        sys.exit("❌ 自动安装失败,请手动运行 scripts/setup_transcribe.py")
    if not deps_ready():

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The CLI defaults --lang to zh and labels it as the default Chinese language, which imposes a specific language choice unless the user explicitly overrides it. This is a natural-language locale policy concern because the script selects a locale by default rather than prompting for or inferring user preference.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/transcribe.py (reported line 105)May include surrounding context.

python
print(f"[transcribe] ffmpeg: {ff_exe}")
    print(f"[transcribe] HF_ENDPOINT: {HF_ENDPOINT}")
    print(f"[transcribe] 运行: {' '.join(cmd)}")
    rc = subprocess.run(cmd)
    if rc.returncode != 0:
        sys.exit(f"❌ whisper 运行失败(返回码 {rc.returncode})。"
                 "若提示模型下载失败,确认网络可达 hf-mirror.com。")

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

Line L23 states that YouTube titles should use '英文/本地语' as a default rule, which imposes a language/locale recommendation in the skill content. Because the file does not frame this as user-selectable guidance or a clearly justified region-specific constraint, it can be read as a locale policy constraint without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and CLI usage/output descriptions are entirely in Chinese, and later runtime messages also use Chinese. This creates a language/locale constraint without any visible opt-in or alternative, which matches the policy concern for forced language selection.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.