Back to skill

Security audit

music-to-video

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed music-to-video workflow that uses expected local files, commands, media assets, and rendering tools, with no evidence of deception or unrelated data access.

Install only if you are comfortable with a skill that runs HyperFrames commands, may install Python audio libraries, writes video project files under videos/<project>/, copies user-selected media into the project, and may update related HyperFrames skills. Avoid flash/strobe templates or add a safe-mode review if the output may be viewed by photosensitive users.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill instructs the agent to execute shell commands and write files across the project tree, but it does not declare permissions or constraints for those capabilities. That creates a real trust-boundary problem: a caller or platform may treat the skill as low-risk while it can install packages, run CLIs, modify project files, and copy user-provided paths, increasing the chance of unintended command execution or filesystem changes.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The animation includes a bright full-screen flash that rapidly appears and fades, which can trigger discomfort or photosensitive seizure risk in susceptible users. In this skill context, the asset is explicitly designed for music-synced video generation, making repeated use of punch/flash effects more likely and increasing exposure risk if no warning, reduction mode, or safety guard is provided.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.