Back to skill

Security audit

Plex Server

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims: it manages a Plex server and optional Nvidia Shield device using disclosed local commands and stored Plex credentials.

Install only if you are comfortable giving this skill a Plex token with full account/server access and, if using Shield features, ADB control that can reboot the device or restart Plex. Use it on a trusted machine, keep the config file private, and revoke or rotate the Plex token if the machine or file is exposed.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/shield-cli.js:63