Back to skill

Security audit

Jable Downloader Lite

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but its downloader can be steered to contact non-Jable URLs and pass unvalidated remote media URLs into a local downloader.

Install only if you are comfortable with a skill that downloads adult media, creates organized folders under your Videos directory, uses external tools, and makes network requests. Before use, restrict inputs to known Jable video IDs or Jable.tv URLs, consider a dedicated output folder, and prefer pinned/trusted installations of yt-dlp and ffmpeg. The publisher should add URL/media validation and explicit permission scoping before this is treated as low-risk.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/jable_downloader.py:28
Finding

Unrestricted URL Fetching Enables Server-Side Request Forgery

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/jable_downloader.py:43
Finding

Untrusted HLS Value Is Passed to yt-dlp Without URL or Argument Validation

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:12
Finding

Third-Party Downloader Dependency Is Installed Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises behavior that requires network access, shell execution, and filesystem interaction, but it does not declare any explicit tool scope or permissions. This weakens reviewability and user consent because an agent may exercise powerful capabilities not clearly bounded by the manifest.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
Before using, ensure these tools are installed:

- **yt-dlp** — Video download engine (`pip install yt-dlp` or `brew install yt-dlp`)
- **ffmpeg** — Video processing (`sudo apt install ffmpeg` or `brew install ffmpeg`)
- **xdg-user-dir** — (Linux only) For finding default Videos folder

## Usage

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill writes files into the user's Videos folder and reorganizes them by actress name, but the description does not foreground this as a side effect requiring clear user awareness. Silent or under-disclosed file creation can lead to privacy issues, unwanted disk consumption, and user surprise, especially given the sensitive nature of the content being downloaded.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/jable_downloader.py (reported line 22)May include surrounding context.

python
system = platform.system()
    if system == "Linux":
        try:
            res = subprocess.run(['xdg-user-dir', 'VIDEOS'], capture_output=True, text=True, check=True)
            path = Path(res.stdout.strip())
            if path.exists(): return str(path)
        except: pass

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/jable_downloader.py (reported line 116)May include surrounding context.

python
cmd = ['yt-dlp', '--force-ipv4', '--concurrent-fragments', '16', '--referer', 'https://jable.tv/', '-o', output_path, m3u8_url]
        
        print(f"⬇️ Downloading: {title} (attempt {attempt + 1}/{max_retries})")
        process = subprocess.Popen(cmd, stdout=subprocess.PIPE, stderr=subprocess.STDOUT, text=True, bufsize=1)
        
        for line in process.stdout:
            if '[download]' in line:

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script makes HTTP requests to jable.tv to retrieve page content and later downloads media data, but there is no docstring, comment, or upfront warning that running the tool will contact an external service and transmit requested video identifiers/search terms. The existing progress prints describe activity after execution begins, but they do not function as a disclosure of the privacy/network behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The script creates directories, writes downloaded MP4 files, moves them into actress-named folders, and deletes temporary files, but there is no user-facing warning or documentation describing these filesystem changes before they occur. Although some status messages appear during cleanup and download, they do not clearly disclose the full extent of file modifications in advance.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.