Back to skill

Security audit

FFHub FFmpeg Skill

Security checks for vulnerabilities and agentic risk

Overview

This cloud media-processing skill is mostly purpose-aligned, but it unnecessarily prints the user's FFHub API key and uploads local media to temporary public URLs without an explicit consent step.

Review this skill before installing. It is not evidence of malware, but only use it with media you are comfortable sending to FFHub, and avoid running the API-key echo step; check whether FFHUB_API_KEY is set without printing its value and rotate the key if it has already been exposed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:14
Finding

API Key Exposed Through Shell Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 14–18
Vulnerability Type: Credential exposure through plaintext shell output
Risk Level: Medium

Vulnerable Code

markdown
Read the API key from the environment variable `FFHUB_API_KEY`:

```bash
echo $FFHUB_API_KEY
text

### Technical Analysis

The skill instructs the agent to execute `echo $FFHUB_API_KEY`, which writes the complete bearer credential to standard output. Tool output may be retained in agent transcripts, execution logs, debugging systems, or other observability infrastructure.

Displaying the secret is unnecessary to determine whether the environment variable is configured. Because the same key is subsequently intended for use as a bearer token in FFHub API requests, anyone who obtains the exposed value may be able to authenticate as the affected user.

### Attack Path

1. A user invokes the FFHub skill with `FFHUB_API_KEY` configured.
2. The agent follows the authentication instructions and runs `echo $FFHUB_API_KEY`.
3. The complete API key appears in captured shell output.
4. A party with access to the conversation transcript, tool logs, or execution telemetry obtains the key.
5. The exposed key is reused against FFHub endpoints until it is revoked or expires.

This finding does not establish that logs are publicly accessible; exploitation requires access to a location where the shell output was retained.

### Impact Assessment

Successful exploitation could permit unauthorized FFHub API access within the permissions assigned to the exposed key. Potential effects include consumption of the victim's API quota, submission or inspection of processing tasks where authorized by the API, and access to associated task results. This issue does not provide local system privilege escalation by itself.
Remediation
View remediation

Remediation Suggestions

Do not print the credential. Check only whether the variable is defined and nonempty:

bash
if [ -z "${FFHUB_API_KEY:-}" ]; then
  echo "FFHUB_API_KEY is not set"
  exit 1
fi

Additional hardening measures:

  • Pass the key directly to curl without displaying or logging it.
  • Ensure shell tracing such as set -x is disabled while handling credentials.
  • Redact authorization headers and secret environment variables from agent transcripts and execution logs.
  • Use narrowly scoped, short-lived API keys where supported.
  • Revoke and rotate any key that may already have been exposed through tool output.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

External Transmission

Medium
Category
Data Exfiltration
Confidence
77% confidence
Finding

The skill is designed to perform external network operations via curl, which means user data and generated commands may be transmitted off-platform to a third-party service. In this context, external transmission is core functionality, but it still represents a real security and privacy boundary crossing that can expose user content, metadata, and processing details.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: ffmpeg
description: Process video/audio files using FFHub.io cloud FFmpeg API. Use when the user wants to convert, compress, trim, resize, extract audio, generate thumbnails, or perform any FFmpeg operation on media files.
argument-hint: "[describe what you want to do with your video/audio file]"
allowed-tools: Bash(curl *), Bash(echo *), Bash(jq *)
---

# FFHub - Cloud FFmpeg Processing

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This endpoint submits FFmpeg tasks to an external API, including user-specified commands and input URLs, so it creates a direct channel for transmitting user data and job parameters to a third party. Because the command may embed media URLs and processing options, misuse or insufficient disclosure could leak sensitive content locations or processing intent.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

Create Task

bash
curl -s -X POST https://api.ffhub.io/v1/tasks \
  -H "Authorization: Bearer $FFHUB_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

Query Task

bash
curl -s https://api.ffhub.io/v1/tasks/TASK_ID

Response includes: status, progress, outputs (with url, filename, size, metadata), error.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 146)May include surrounding context.

Query Task

bash
curl -s https://api.ffhub.io/v1/tasks/TASK_ID

Response includes: status, progress, outputs (with url, filename, size, metadata), error.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly instructs uploading a user-provided local media file to a third-party cloud service and converting it into a public URL, but it does not require an explicit user-facing consent or privacy warning before transmission. This can expose sensitive media content, metadata, and derived outputs to an external service and potentially to anyone with the returned URL, especially since the URL is described as public and time-limited rather than access-controlled.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill reads an API credential from an environment variable and uses it in outbound Authorization headers, but it provides no user-facing notice that a secret will be used for a third-party request. While using environment variables is standard practice, the lack of disclosure and guardrails around external transmission of credentials increases the chance of unintended secret use in an untrusted or poorly understood integration.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.