Back to skill

Security audit

TikTok Video Maker

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for generating videos, but it can expose user-submitted media through public-by-default videos and automatic share links without clear consent controls.

Review this skill carefully before installing. It is not showing hidden code or destructive behavior, but it sends your script and image to LovelyBots and the documented API can make generated videos public unless `public: false` is set. Use it only with content you are comfortable uploading to LovelyBots, require private generation by default, and avoid sharing or logging `share_url` unless you intend others to access the video.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:293
Finding

Generated User Media Is Public by Default

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:293-294
Vulnerability Type: Insecure privacy configuration
Risk Level: Medium

Vulnerable Code

text
| image | file or string | ✓ | Unified image input. Can be multipart file upload, http/https URL, or base64/data URL |
| public | boolean |  | Whether the video appears in the public feed (default: true) |

Technical Analysis

The Skill accepts potentially sensitive user content, including portrait images, base64-encoded images, and scripts. However, the documented API behavior makes generated videos public when the optional public field is omitted.

Although the initial JSON example explicitly specifies "public": false, the general workflow and request schema do not require agents to preserve that setting or obtain explicit consent before enabling public publication. An agent-generated request that omits the field will therefore rely on the API's public-by-default behavior.

This violates privacy-by-default principles. Security-sensitive visibility controls should fail closed, especially when processing personal images or user-authored content.

Attack Path

  1. A user provides a portrait image and script for video generation.
  2. The agent constructs a request to the LovelyBots API.
  3. The agent omits the optional public field because the workflow does not require it.
  4. The API applies its documented default value of true.
  5. The generated video is published to the service's public feed without an explicit publication decision from the user.

Impact Assessment

This issue may expose user-submitted images, generated likenesses, scripts, and resulting videos to the public. The affected scope is limited to content submitted through this Skill and generated by the external service; it does not grant local system privileges or access to unrelated files.

Potential consequences include unintended disclosure of personal media, reputati ...[truncated 54 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require "public": false in every request template and agent workflow.
  2. Instruct agents never to omit the public field.
  3. Set "public": true only after obtaining explicit, informed user consent for that specific video.
  4. Add a prominent warning explaining that public videos may appear in the LovelyBots public feed.
  5. If the API is under the project owner's control, change the server-side default to false.
  6. Reject or pause ambiguous requests rather than assuming that publication is authorized.
  7. Add tests verifying that requests without explicit publication consent are always submitted with "public": false.

T08 · Insecure Dependencies

Warning
Location
PUBLISH.md:12
Finding

Unpinned Global Installation of a Third-Party npm Package

Content
View full analysis

Vulnerability Details

File Location: PUBLISH.md:12-15
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code

bash
# Install the ClawHub CLI
npm install -g clawhub

# Authenticate with GitHub
clawhub login

Technical Analysis

The publishing instructions install the mutable latest version of the clawhub npm package globally. No exact version, lockfile, package integrity value, provenance check, or lifecycle-script restriction is specified.

npm packages can execute lifecycle scripts during installation. Consequently, if a future package release or its distribution channel is compromised, following these instructions could execute attacker-controlled code with the privileges of the publishing user. Global installation also makes the package broadly available in the user's environment and increases the persistence and impact of a compromised release.

The audit found no evidence that the named package is currently malicious. The vulnerability is the unsafe and non-reproducible dependency acquisition method documented by the project.

Attack Path

  1. An attacker compromises the npm package, a maintainer account, or a future package release.
  2. The compromised release becomes the version resolved by the unpinned package name.
  3. A publisher follows PUBLISH.md and runs npm install -g clawhub.
  4. npm downloads the compromised release.
  5. Malicious package code or lifecycle scripts execute with the publisher's account privileges.
  6. The attacker could access data and credentials available to that account, including publishing or GitHub-related credentials depending on the environment and execution timing.

Impact Assessment

Exploitation could provide arbitrary code execution with the privileges of the user running npm. The resulting scope may include that user's files, environment variables, npm configuration, and credentials access ...[truncated 241 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to a reviewed exact version, for example clawhub@X.Y.Z, rather than resolving the mutable latest release.
  2. Record and verify the expected package integrity hash and provenance before installation.
  3. Prefer a project-local development dependency governed by a committed lockfile instead of a global installation.
  4. Use npm ci for reproducible installation when managing the dependency through a project manifest and lockfile.
  5. Run the CLI in an isolated, least-privileged environment without unrelated secrets.
  6. Disable npm lifecycle scripts with --ignore-scripts if the verified CLI does not require them.
  7. Review package ownership, release signatures or provenance, dependency changes, and published contents before updating the pinned version.
  8. Document a controlled update process that audits each new version before changing the pin.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (17)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · PUBLISH.md (reported line 63)May include surrounding context.

md
- [ ] Poll response includes `video_url` only once the job is completed
- [ ] Production base URL is https://api.lovelybots.com/api (not the ngrok URL)

If any fields differ, update SKILL.md before publishing.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

This section explicitly instructs agents to send authenticated requests containing user-provided scripts and images to an external third-party API. In the context of an agent skill, that is a real data-transmission security concern because sensitive user content or secrets embedded in prompts/images could be forwarded off-platform if the skill is invoked without adequate disclosure, scoping, or validation.

Content

Scanner excerpt · README.md (reported line 64)May include surrounding context.

md
## Critical Tips for Agents

1. Use `https://api.lovelybots.com/api` for automation calls, not the website host.
2. Always include `Authorization: Bearer $LOVELYBOTS_API_KEY`.
3. Treat IDs as UUID strings (`video.id`, `voice_id`), not integers.
4. Poll with timeout/retry guards and stop on terminal status (`completed`/`failed`) or API errors.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · PUBLISH.md (reported line 61)May include surrounding context.

md
Generate talking videos programmatically using the LovelyBots API. This skill lets you queue a video from a script and source image, poll until it's ready, and return the final video URL.

Get your API key at: https://lovelybots.com/developer
API base URL for bots: https://api.lovelybots.com/api

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 21)May include surrounding context.

md
Generate talking videos programmatically using the LovelyBots API. This skill lets you queue a video from a script and source image, poll until it's ready, and return the final video URL.

Get your API key at: https://lovelybots.com/developer
API base URL for bots: https://api.lovelybots.com/api

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 88)May include surrounding context.

md
Generate talking videos programmatically using the LovelyBots API. This skill lets you queue a video from a script and source image, poll until it's ready, and return the final video URL.

Get your API key at: https://lovelybots.com/developer
API base URL for bots: https://api.lovelybots.com/api

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 94)May include surrounding context.

md
Generate talking videos programmatically using the LovelyBots API. This skill lets you queue a video from a script and source image, poll until it's ready, and return the final video URL.

Get your API key at: https://lovelybots.com/developer
API base URL for bots: https://api.lovelybots.com/api

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
Generate talking videos programmatically using the LovelyBots API. This skill lets you queue a video from a script and source image, poll until it's ready, and return the final video URL.

Get your API key at: https://lovelybots.com/developer
API base URL for bots: https://api.lovelybots.com/api

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
Generate talking videos programmatically using the LovelyBots API. This skill lets you queue a video from a script and source image, poll until it's ready, and return the final video URL.

Get your API key at: https://lovelybots.com/developer
API base URL for bots: https://api.lovelybots.com/api

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

md
Generate talking videos programmatically using the LovelyBots API. This skill lets you queue a video from a script and source image, poll until it's ready, and return the final video URL.

Get your API key at: https://lovelybots.com/developer
API base URL for bots: https://api.lovelybots.com/api

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
Generate talking videos programmatically using the LovelyBots API. This skill lets you queue a video from a script and source image, poll until it's ready, and return the final video URL.

Get your API key at: https://lovelybots.com/developer
API base URL for bots: https://api.lovelybots.com/api

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 215)May include surrounding context.

md
Generate talking videos programmatically using the LovelyBots API. This skill lets you queue a video from a script and source image, poll until it's ready, and return the final video URL.

Get your API key at: https://lovelybots.com/developer
API base URL for bots: https://api.lovelybots.com/api

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 337)May include surrounding context.

md
Generate talking videos programmatically using the LovelyBots API. This skill lets you queue a video from a script and source image, poll until it's ready, and return the final video URL.

Get your API key at: https://lovelybots.com/developer
API base URL for bots: https://api.lovelybots.com/api

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 345)May include surrounding context.

md
Generate talking videos programmatically using the LovelyBots API. This skill lets you queue a video from a script and source image, poll until it's ready, and return the final video URL.

Get your API key at: https://lovelybots.com/developer
API base URL for bots: https://api.lovelybots.com/api

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

  • Use 9:16 orientation (for example 1080x1920).
bash
curl -X POST https://api.lovelybots.com/api/create \
  -H "Authorization: Bearer $LOVELYBOTS_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly recommends exposing share_url during intermediate status updates, but the examples indicate this URL is a shareable access link, possibly including an unguessable token. Disclosing it by default can leak access to in-progress or private video artifacts to unintended recipients, especially in multi-user agent contexts, logs, chat transcripts, or notifications.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The recommended status template tells agents to disclose a shareable link before job completion. If that URL grants access without additional authentication, early disclosure increases the chance of unintended sharing, exposure in system logs, or access by downstream tools before the user intends publication.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.