Back to skill

Security audit

Jogg Lip Sync

Security checks for vulnerabilities and agentic risk

Overview

This skill uses your Jogg API key to upload the video and audio you choose for lip-sync processing, with no evidence of hidden or unrelated behavior.

Install only if you are comfortable sending the chosen video and audio to Jogg using your API key. Keep JOGG_BASE_URL unset or pointed at the legitimate Jogg API, do not use a skill-local .env from an untrusted source, and consider using a dedicated API key with limited exposure.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
run.sh:54
Finding

Unvalidated API Base URL Exposes Credentials and Enables Media Exfiltration

Content
View full analysis

Vulnerability Details

File Location: run.sh:54, run.sh:156-185, run.sh:247-256
Vulnerability Type: Unvalidated external endpoint configuration and sensitive-data exposure
Risk Level: High

Vulnerable Code

sh
: "${JOGG_BASE_URL:=https://api.jogg.ai}"
sh
if [ -n "$payload" ]; then
  if [ -n "${JOGG_API_PLATFORM:-}" ]; then
    RESPONSE_STATUS=$(curl -sS -o "$body_file" -w "%{http_code}" -X "$method" "$url" \
      -H "X-Api-Key: ${JOGG_API_KEY}" \
      -H "x-api-platform: ${JOGG_API_PLATFORM}" \
      -H "Content-Type: application/json" \
      -d "$payload") || {
      rm -f "$body_file"
      json_error "request failed"
      exit 1
    }
  else
    RESPONSE_STATUS=$(curl -sS -o "$body_file" -w "%{http_code}" -X "$method" "$url" \
      -H "X-Api-Key: ${JOGG_API_KEY}" \
      -H "Content-Type: application/json" \
      -d "$payload") || {
      rm -f "$body_file"
      json_error "request failed"
      exit 1
    }
  fi
else
  if [ -n "${JOGG_API_PLATFORM:-}" ]; then
    RESPONSE_STATUS=$(curl -sS -o "$body_file" -w "%{http_code}" -X "$method" "$url" \
      -H "X-Api-Key: ${JOGG_API_KEY}" \
      -H "x-api-platform: ${JOGG_API_PLATFORM}") || {
      rm -f "$body_file"
      json_error "request failed"
      exit 1
    }
  else
    RESPONSE_STATUS=$(curl -sS -o "$body_file" -w "%{http_code}" -X "$method" "$url" \
      -H "X-Api-Key: ${JOGG_API_KEY}") || {
      rm -f "$body_file"
      json_error "request failed"
      exit 1
    }
  fi
fi
sh
api_request "POST" "${JOGG_BASE_URL%/}/v2/upload/asset" "$payload"
api_success_data
sign_url=$(printf '%s' "$LAST_JSON" | jq -r '.sign_url')
asset_url=$(printf '%s' "$LAST_JSON" | jq -r '.asset_url')

upload_status_file=$(mktemp)
run_with_heartbeat "uploading binary to storage" \
  sh -c '
    curl -sS -o /dev/null -w "%{http_code}" -X PUT "$1" -H "Content-Type: $2" --data-binary "@$3" > "$4"
  ' sh "$sign_url" "$content_type" "$media_input" "$upload_status_file" || {

...[truncated 2247 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the production JOGG_BASE_URL override and use a constant trusted endpoint where custom endpoints are not explicitly required.
  2. If configurability is necessary, parse and validate the URL before any request:
    • Require the https scheme.
    • Require an exact allowlisted hostname such as api.jogg.ai.
    • Reject embedded credentials, unexpected ports, malformed hosts, and non-HTTPS URLs.
  3. Validate every returned sign_url before uploading:
    • Require HTTPS.
    • Permit only documented Jogg storage domains or an authoritative allowlist.
    • Reject loopback, link-local, private-network, and unapproved external destinations.
  4. Configure curl to fail securely, such as with --fail-with-body, and use explicit connection and total timeouts.
  5. Do not forward authentication headers across redirects. Either reject redirects or constrain them to approved HTTPS hosts.
  6. Treat the Skill-local .env as sensitive configuration:
    • Require restrictive filesystem permissions.
    • Ensure it is not writable by untrusted users.
    • Document that environment overrides can affect credential destinations.
  7. Consider separating authenticated API communication from media upload logic so that the API key can only ever be sent to a fixed, trusted origin.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
- `sh "run.sh"`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
- `sh "run.sh"`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

md
- `sh "run.sh"`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
- `sh "run.sh"`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
- `sh "run.sh"`

Credential Access

High
Category
Privilege Escalation
Confidence
92% confidence
Finding

The skill automatically loads a .env file from its own directory and later uses those values for sensitive settings such as API keys and destination URLs. In a shared or supply-chain setting, a writable bundled .env can inject secrets or malicious endpoints, enabling credential theft or request redirection.

Content

Scanner excerpt · run.sh (reported line 5)May include surrounding context.

sh
set -eu

SCRIPT_DIR=$(CDPATH= cd -- "$(dirname -- "$0")" && pwd)
ENV_FILE="$SCRIPT_DIR/.env"

load_default_env() {
  [ -f "$ENV_FILE" ] || return 0

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · run.sh (reported line 84)May include surrounding context.

sh
Run or query Jogg lip sync tasks.

Environment:
  .env in this directory is auto-loaded as defaults.
EOF
}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · run.sh (reported line 104)May include surrounding context.

sh
Run or query Jogg lip sync tasks.

Environment:
  .env in this directory is auto-loaded as defaults.
EOF
}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · run.sh (reported line 103)May include surrounding context.

sh
jq -cn \
    --arg error "missing required configuration: $missing_key" \
    --arg missing_key "$missing_key" \
    --arg env_file ".env" \
    --arg action "update .env or set the environment variable before running again" \
    '{
      error: $error,

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill invokes shell execution via sh "run.sh" but does not declare an explicit tool scope such as permissions or allowed-tools. This weakens policy enforcement and reviewability, making it easier for an agent runtime to execute local commands without a clearly bounded authorization model.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description does not clearly warn that using it will upload provided video and audio to an external service using the user's API key. This can lead to inadvertent disclosure of sensitive media and metadata, especially when local file paths are accepted and the runner performs authenticated remote transfers.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad enough to activate on ordinary user requests such as asking to "run lip sync" or providing media, without clearly signaling that local files may be processed and uploaded to a third-party API. Overbroad activation increases the chance of unintended execution of shell commands and authenticated network actions on sensitive user media.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This code sends data and the API key to a URL that is not fixed at build time because JOGG_BASE_URL is taken from the environment/.env. In an agent-skill context, a malicious or tampered configuration can redirect requests and credentials to an attacker-controlled host, making this more dangerous than ordinary expected API communication.

Content

Scanner excerpt · run.sh (reported line 155)May include surrounding context.

sh
if [ -n "$payload" ]; then
    if [ -n "${JOGG_API_PLATFORM:-}" ]; then
      RESPONSE_STATUS=$(curl -sS -o "$body_file" -w "%{http_code}" -X "$method" "$url" \
        -H "X-Api-Key: ${JOGG_API_KEY}" \
        -H "x-api-platform: ${JOGG_API_PLATFORM}" \
        -H "Content-Type: application/json" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This is the same external transmission path without the platform header, still sending the X-Api-Key and request payload to a runtime-controlled URL. If JOGG_BASE_URL is modified, the skill can exfiltrate credentials and media metadata to an attacker-controlled endpoint.

Content

Scanner excerpt · run.sh (reported line 165)May include surrounding context.

sh
exit 1
        }
    else
      RESPONSE_STATUS=$(curl -sS -o "$body_file" -w "%{http_code}" -X "$method" "$url" \
        -H "X-Api-Key: ${JOGG_API_KEY}" \
        -H "Content-Type: application/json" \
        -d "$payload") || {

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The script uploads the full local media file to sign_url returned by the remote API with no host validation. If the upstream API or base URL is malicious, this becomes a direct file-exfiltration primitive for arbitrary local files supplied as --video/--audio.

Content

Scanner excerpt · run.sh (reported line 255)May include surrounding context.

sh
upload_status_file=$(mktemp)
  run_with_heartbeat "uploading binary to storage" \
    sh -c '
      curl -sS -o /dev/null -w "%{http_code}" -X PUT "$1" -H "Content-Type: $2" --data-binary "@$3" > "$4"
    ' sh "$sign_url" "$content_type" "$media_input" "$upload_status_file" || {
      rm -f "$upload_status_file"
      json_error "upload failed"

Static analysis

No suspicious patterns detected.