Back to skill

Security audit

tibetan-cinematic-video

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrow Google Veo video-generation workflow, but users should know it sends the selected image to a remote video service and writes the result locally.

Install only if you are comfortable uploading the selected image to the configured Veo service and saving the generated MP4 under ~/.openclaw/workspace/tibetanProc/. Avoid sensitive personal, confidential, or copyrighted images unless you understand the endpoint, retention, and privacy handling.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list contains broad terms like "monastery," "prayer wheel," and "Himalayan" that could match ordinary user requests and invoke the skill unexpectedly. Because this skill uploads a user image to Google Veo/internal endpoints and writes output files, unintended invocation increases the risk of surprise data transfer and unintended side effects.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs the agent to send the user's image to Google Veo or an internal Veo endpoint, but the description does not clearly warn the user that their image leaves the local environment. This creates a privacy and consent issue, especially for sensitive or personal images, because users may not realize third-party or internal remote processing will occur.

Static analysis

No suspicious patterns detected.