Back to skill

Security audit

onepress-deck-video

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently uses OnePress to turn decks into videos, with disclosed account connection, upload, polling, and MP4 download behavior.

Install only if you are comfortable sending deck contents to OnePress for processing and storing a OnePress API key in your agent environment or secret store. Avoid using it for highly sensitive decks unless your OnePress account and workspace policies permit that transfer.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README instructs users to create and use a raw ONEPRESS_API_KEY, while the skill metadata says authentication should occur through browser-confirmed pairing with no key copying. This mismatch can cause users to expose long-lived credentials unnecessarily, increasing the risk of secret leakage, phishing-style credential collection, or use of a less secure auth path than intended.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

· {"status":"denied"} · {"status":"expired"} (start over)

text

5. Store `api_key` in the host's secret/env store as `ONEPRESS_API_KEY`. Never
ask the user to paste a key into chat, and never log it. Users can revoke it
anytime in OnePress Settings (or create one manually at
**Settings → Account → API keys**).

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 132)May include surrounding context.

· {"status":"denied"} · {"status":"expired"} (start over)

text

5. Store `api_key` in the host's secret/env store as `ONEPRESS_API_KEY`. Never
ask the user to paste a key into chat, and never log it. Users can revoke it
anytime in OnePress Settings (or create one manually at
**Settings → Account → API keys**).

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill directs the agent to upload a local deck file to OnePress, but it does not require an explicit user-facing disclosure or confirmation that the file contents will be transmitted to a third-party service. This can lead to unintended exfiltration of sensitive slide content, especially when users may assume the agent is operating locally or may not realize the full file is being sent off-platform.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs downloading the generated MP4 and saving it to the user's working directory without an explicit notice or confirmation about the local file write. While lower risk than data exfiltration, silent writes can surprise users, overwrite expected workspace contents, or create privacy issues if the environment is shared or monitored.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.