Back to skill

Security audit

video by remotion

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a real Remotion video tool, but its generated project scripts can be abused through untrusted config or content to run shell commands or write outside the project folder.

Review before installing. Use it only with config and subtitle JSON you trust, run generated projects in an isolated directory or disposable environment, avoid sensitive narration with Edge TTS, and prefer a version with fixed path containment, safe subprocess invocation, and locked dependencies.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
assets/project-template/scripts/pipeline.py:228
Finding

Arbitrary Command Execution Through Unquoted Python Environment Configuration

Content
View full analysis
/dev/null)" && ' f"conda activate {conda_name} && " f"python {tts_script_path} " f"--config {config_path} --content {content_path}" ) print(f" [conda] env={conda_name}") print(f" Running: {shell_cmd}\n") try: subprocess.run( ["bash", "-c", shell_cmd], check=True, cwd=root, ) except subprocess.CalledProcessError as e: print(f"\n❌ TTS gene ...[truncated 2461 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
assets/project-template/scripts/tts_edge.py:129
Finding

Path Traversal Permits File Writes Outside the Generated Project

Content
View full analysis
Remediation
View remediation
str: base_real = os.path.realpath(base) candidate = os.path.realpath(os.path.join(base_real, *parts)) if os.path.commonpath([base_real, candidate]) != base_real: raise ValueError(f"Path escapes allowed directory: {candidate}") return candidate ``` 4. Apply containment checks to every audio, subtitle, manifest, build, render-property, temporary, and output-video path. 5. Reject absolute `audioDir` and `buildDir` values unless an explicit opt-in permits external output. 6. Prefer fixed application-owned output directories rather than accepting unrestricted configuration paths. 7. Check for symbolic-link escapes immediately before opening or replacing a file. Where supported, use safer file-opening semantics that do not follow symlinks. 8. Create files atomically with restrictive permissions and fail rather than silently writing outside approved locations. 9. Add tests for absolute paths, nested `../`, platform-specific separators, Windows drive paths, and symlink-based escapes. ]]>

T08 · Insecure Dependencies

Warning
Location
assets/project-template/requirements.txt:1
Finding

Unpinned Dependency Installation Creates Supply-Chain Exposure

Content
View full analysis
=6.1.0 # Qwen TTS (local MLX model) — only needed for `make tts-qwen` / `make pipeline-qwen` # Install these in your conda/venv environment: # mlx-audio>=0.2.0 # soundfile>=0.12.0 # numpy>=1.24.0 ``` The Makefile installs dependencies without integrity enforcement: ```make ## Install npm dependencies install: init-config npm install ``` ```make ## Install Qwen TTS dependencies into the configured env deps-qwen: @echo "Installing Qwen TTS deps (env_type=$(ENV_TYPE))..." $(ACTIVATE_PYTHON) -m pip install mlx-audio soundfile numpy @echo "✅ Qwen TTS deps installed" ``` The npm manifest pins Remotion packages exactly but uses version ranges for other packages, and the audited project structure contains no lockfile: ```json "dependencies": { "@remotion/bundler": "4.0.448", "@remotion/captions": "4.0.448", "@remotion/cli": "4.0.448", "@remotion/media": "4.0.448", "@remotion/renderer": "4.0.448", "@remotion/transitions": "4.0.448", "react": "^18.3.1", "react-dom": "^18.3.1", "remotion": "4.0.448" }, "devDependencies": { "@types/react": "^18.3.12", "@types/react-dom": "^18.3.1", "@types/node": "^22.10.0", "eslint": "^9.15.0", "prettier": "^3.4.2", "typescript": "^5.7.2" } ``` ### Technical Analysis Dependency versions are resolved at installation time rather than from a complete reviewed lock set: - `edge-tts>=6.1.0` allows all future compatible or incompatible releases. - `pip install mlx-audio soundfile numpy` has no version constraints. - Several npm packages ...[truncated 1821 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (53)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill promises that all operations must go through make, but elsewhere documents or implies direct subprocess execution (ffmpeg, npx remotion render, npx tsc, manual shell commands). This mismatch weakens trust boundaries: an agent or user may believe execution is constrained to a vetted wrapper when the actual workflow permits broader command execution and side effects.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · assets/project-template/Makefile.txt (reported line 299)May include surrounding context.

text
## Remove generated audio and video output
clean:
	rm -rf $(AUDIO_DIR)/*.mp3 $(AUDIO_DIR)/*.wav $(AUDIO_DIR)/*.srt
	rm -rf $(OUT_DIR)

## Remove TTS manifest to force re-generation of all audio

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · assets/project-template/Makefile.txt (reported line 304)May include surrounding context.

text
## Remove TTS manifest to force re-generation of all audio
clean-tts:
	rm -f $(AUDIO_DIR)/.tts_manifest.json
	@echo "✅ TTS manifest removed. Next TTS run will regenerate all audio."

## Remove everything: output + node_modules + cache

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill clearly instructs use of filesystem and shell operations (python, make, node, unzip, chmod) but does not declare any explicit tool scope or permission boundaries. In an agent environment, this increases the risk of over-broad execution because the agent may invoke powerful local capabilities without user-visible restriction or least-privilege controls.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description says to use the skill when users want to create educational/explainer videos, animated presentations, data visualization videos, or any programmatic video with narration and subtitles. This is a wide natural-language trigger surface without explicit boundaries, exclusions, or concrete invocation phrases, which could cause unintended activation for generic video-related requests.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

The skill documents direct use of npx remotion render as part of the pipeline behavior, which implies execution of Node tooling without a pinned invocation in the skill specification. In agent-driven environments, relying on npx can be unsafe if dependency resolution is not strictly local and locked, as it may execute unexpected package versions or remotely fetched code.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documented multi-speaker example hard-codes zh-CN voice IDs for default narration roles, which can imply a fixed Chinese locale for output. The file does not pair this with an explicit user opt-in or a statement that the skill is intended only for Chinese-language content, creating a potential language/locale policy issue.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The comment for tts says it generates audio using the default engine from config, but the implementation unconditionally invokes scripts/tts_edge.py. This actively contradicts the documented behavior and would ignore a configuration selecting Qwen as the default engine.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The tts-edge target sends user-provided script content to an online TTS service, but the Makefile provides no explicit privacy warning or consent gate at the point of use. In this skill context, users may process proprietary or sensitive narration text, so silent network transmission can cause unintended data disclosure.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The target is documented as 'Full pipeline ... (default engine)', but unlike pipeline-qwen and pipeline-edge, it does not pass an engine flag and there is no evidence in this file that it resolves the configured engine. Given the parallel inconsistency in the tts target, the Makefile documentation appears to promise config-driven behavior that the recipe does not implement here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This manifest/config file specifies Chinese-only voice and language settings such as "zh-CN-YunyangNeural" and "lang_code": "zh". Under the policy, forcing a specific language or locale without documented user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest explicitly states that all operations must use make commands and never bare CLI commands. This script is documented and implemented as a directly invokable Python entrypoint (python scripts/pipeline.py) and internally runs bare npx, ffmpeg, ffprobe, bash, and Python commands, which does not match that declared operational contract.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring actively instructs users to execute python scripts/pipeline.py with various flags. That directly contradicts the skill's stated intent that all operations must be performed via make commands rather than bare CLI usage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This function explicitly overwrites the original audio file after ffmpeg normalization, and the pipeline also writes render-props.json and video output later in execution. Although some inline logging exists when normalization runs, there is no prominent warning in the top-level usage/help text that existing files may be modified or replaced.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.