Back to skill

Security audit

jftech-open-pro-video-record

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed JFTech camera recording playback tool, but users should treat the credentials and video links as sensitive.

Install only if you trust the publisher and are authorized to access the referenced JFTech devices. Keep JF_APPSECRET and JF_PASSWORD protected, use least-privilege credentials, keep JF_ENDPOINT on an official JFTech host, and avoid sharing printed playback or download URLs.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
80% confidence
Finding
The skill enables retrieval, playback, and download of surveillance recordings, which are highly sensitive and can expose private activities, locations, and identities. While the capability is legitimate for this skill's purpose, the documentation lacks a clear privacy warning, authorization expectation, or user-consent guidance, increasing the risk of misuse or inappropriate access.

Static analysis

No suspicious patterns detected.