Back to skill

Security audit

HiAPI Video Prompt Generator

Security checks for vulnerabilities and agentic risk

Overview

The skill's prompt-generation purpose is coherent, but its updater and installer give remote or user-controlled inputs too much command and persistence authority.

Review this skill before installing, and avoid the one-line npx installer unless it is pinned to a reviewed commit or release. Do not let an agent automatically run update commands printed by the checker; prefer manual installation from a verified source and inspect any target path or environment variable used for installation.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/check-update.mjs:28
Finding

Remote Manifest Can Supply an Arbitrary Update Command for Agent Execution

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/install.mjs:100
Finding

Shell Command Injection Through Installer Target Path

Content
View full analysis
a.startsWith(prefix)); return hit ? hit.slice(prefix.length).replace(/^~(?=$|\/)/, homedir()) : null; } ``` `scripts/install.mjs:42-45`: ```js if (explicitTarget) { return [{ label: 'explicit', dir: explicitTarget }]; } if (env.AGENT_SKILLS_DIR) { return [{ label: '$AGENT_SKILLS_DIR', dir: env.AGENT_SKILLS_DIR }]; } ``` `scripts/install.mjs:100-108`: ```js function installTo(target) { mkdirSync(target.dir, { recursive: true }); const destination = join(target.dir, SKILL_FOLDER); if (existsSync(destination)) { console.log(`[${DISPLAY_NAME}] ${destination} exists — replacing.`); rmSync(destination, { recursive: true, force: true }); } console.log(`[${DISPLAY_NAME}] Cloning into ${destination} …`); execSync(`git clone --depth 1 ${REPO_URL} "${destination}"`, { stdio: 'inherit' }); } ``` ### Technical Analysis The values accepted through `--target`, `--skills-dir`, and `AGENT_SKILLS_DIR` flow into `target.dir` and then into `destination`. That destination is interpolated into a string passed to `execSync`, which executes through a shell by default. Wrapping the destination in double quotes is not sufficient shell escaping. Shell command substitutions such as `$()` and backticks remain active inside double quotes, and an embedded double quote can terminate the quoted argument and introduce additional shell syntax. The filesystem calls do not neutralize these metacharacters before the same value reaches the shell. This flaw is reachable whenever an attacker can influence installer arguments or environment variables. It does not require modification of the repository itself. ### Attack Path 1. An attacker convinces a user or ...[truncated 1241 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/install.mjs:100
Finding

Unpinned Remote Installation Destructively Replaces Existing Skill

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (32)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README instructs users to install and execute code directly from a GitHub repository via npx -y github:... without pinning to a specific commit, tag, or verified release. That creates a supply-chain risk: if the repository is compromised or changed later, users may run unexpected code during installation with the same trust as the original skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This command executes installer code fetched from GitHub without a pinned version, so the exact code run can change over time. In an agent-skill context, installation often writes into trusted agent skill directories, which increases the blast radius if upstream content is modified maliciously.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The --codex install example still relies on npx -y github:... without immutable version pinning. A compromised upstream repository or account could cause arbitrary code execution on install and persistence inside ~/.codex/skills.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The --claude variant has the same unpinned remote execution issue: it fetches and runs mutable GitHub content at install time. Because it targets a privileged agent skill path, successful exploitation could persist attacker-controlled behavior in future agent sessions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This custom --target=/path install form still executes an unpinned GitHub installer, preserving the same supply-chain risk. The ability to choose arbitrary target directories may further increase impact if a user points installation at sensitive or broadly trusted locations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The 'Agent Auto-Install Prompt' embeds the same unpinned npx -y github:... command, which is especially risky because it is framed as automation-ready text for an agent to execute. This lowers human review and increases the chance that mutable upstream code is run automatically.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The compatibility section repeats the unpinned GitHub npx install pattern for Codex, exposing users to the same mutable-source execution risk. While this is documentation rather than code in the repository, it is still actionable guidance that can directly lead to compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This Claude Code compatibility example instructs users to execute remote installer code from an unpinned GitHub source. Since it modifies a trusted skill directory, any malicious upstream change could create persistence and affect later agent behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The OpenCode example again uses npx -y github:... without version pinning, creating a repeat supply-chain exposure. The surrounding skill context makes this more dangerous because the install target is an agent skill directory that may be trusted and invoked later without re-review.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The generic custom-target install example still fetches and runs mutable remote code from GitHub. In this context, the skill is designed for agent integration, so compromise could extend beyond one command and influence future automated workflows.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The README instructs users to execute code directly from a GitHub repository via npx -y github:... without pinning to a specific commit, tag, or release. That means future changes to the repository or a repository compromise could cause users to run unexpected code during installation, creating a supply-chain execution risk.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.zh-CN.md (reported line 55)May include surrounding context.

安装脚本会自动检测 Codex(~/.codex/skills)和 Claude Code(~/.claude/skills)。指定 Agent 或自定义目录:

bash
npx -y github:HiAPIAI/hiapi-video-prompt-generator-skill --codex          # 只装到 ~/.codex/skills
npx -y github:HiAPIAI/hiapi-video-prompt-generator-skill --claude         # 只装到 ~/.claude/skills
npx -y github:HiAPIAI/hiapi-video-prompt-generator-skill --target=/path   # 自定义目录
AGENT_SKILLS_DIR=/path npx -y github:HiAPIAI/hiapi-video-prompt-generator-skill -y

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This line recommends running an unpinned GitHub-backed npx install command. Because the fetched installer can change over time, a malicious update or account/repository compromise could result in arbitrary code execution on the user's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The command executes installer code from GitHub without version pinning, so users are trusting the current state of the remote repository at execution time. In an agent-skill ecosystem, that increases exposure because automated systems may follow README installation guidance without human review.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

Using npx -y github:... --target=/path still pulls and runs code from an unpinned GitHub source. If the upstream repository changes or is compromised, the installation behavior may change silently and execute attacker-controlled code in the local environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

Setting AGENT_SKILLS_DIR does not reduce the core risk: the npx -y github:... command still executes unpinned remote code. This creates a supply-chain risk where installation instructions can become an execution vector if the repository or maintainer is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The auto-install prompt tells an agent to run an unpinned GitHub npx command. This is especially risky in an agent context because users may paste it into tools that execute instructions with limited scrutiny, turning README text into an indirect remote-code-execution path.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The compatibility section repeats the unpinned npx -y github:... install pattern. Repetition increases the likelihood of unsafe adoption and normalizes execution of mutable remote code for installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This install command again relies on a mutable GitHub source for npx, allowing silent behavioral drift or compromise-driven code execution. The risk remains supply-chain related even if the current repository is benign.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The OpenCode example uses the same unpinned remote execution pattern. In automation-heavy environments, such instructions can be consumed verbatim, magnifying the chance that compromised upstream code is executed across multiple developer machines.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The Cursor/other-agent install example still executes unpinned GitHub code. The skill context makes this somewhat more dangerous because the project explicitly targets agent tooling, where installation may be semi-automated and trusted more readily than ordinary shell snippets.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill instructs the agent to run a local command and references an environment variable (HIAPI_SKIP_UPDATE_CHECK=1), but the skill declares no explicit tool scope or permissions. That creates an authority gap: an agent may execute shell access or inspect environment-dependent behavior without a clear, least-privilege declaration, which can enable unintended command execution or exposure of sensitive local context if the runtime permits it.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill enables implicit invocation and uses broad default invocation wording, which can cause the agent to trigger this skill in situations where the user did not clearly request it. In a prompt-generation skill, unintended activation can introduce unnecessary data flow into the skill and produce outputs that appear authoritative or source-grounded when the user did not intend to invoke this capability.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The script accepts an update command from a remotely fetched manifest and falls back to an unpinned npx -y github:... source, which can cause users or automation to execute code that is not version-locked. If the GitHub source, manifest, or repository ref is changed or compromised, the suggested update path can lead to arbitrary code execution during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/install.mjs:93