T09 · Insecure Skill Coding Practices
- Location
scripts/animate.js:258- Finding
OS Command Injection Through the User-Controlled Output Path
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a mostly coherent SVG-to-video helper, but it has a confirmed unsafe command-execution path and overstates what it can generate.
Install only if you are comfortable with local command execution and generated files under /tmp. Do not pass output paths from untrusted users or automation until the script replaces shell-based execSync calls with argument-array execution and validates output locations. Treat the advertised generation features as limited templates rather than general LLM video generation.
scripts/animate.js:258OS Command Injection Through the User-Controlled Output Path
The description materially overstates and misrepresents the code. The code is a deterministic template renderer: it inspects the theme/story text for a few keywords and selects one of several predefined SVG generators. There is no LLM usage at all, despite the description centering on 'using text LLM' to generate SVG. The claim of supporting 'any subject' is inaccurate because unsupported inputs fall back to a default running dog. The --story and --scenes options do not create multiple scenes or story structure; the code simply passes story text into the same single-theme frame generator and never uses scenes. Duration handling is also only partially implemented because frames is initialized to 24, so the conditional recalculation from duration rarely applies. While the code genuinely does synthesize SVG frames into a video via rsvg-convert and ffmpeg, the declared purpose does not accurately represent the actual scope or mechanism.
Referenced artifact was not completely inspected
使用 `scripts/animate.js` 简化流程:
Referenced artifact was not completely inspected
使用 `scripts/animate.js` 简化流程:
Referenced artifact was not completely inspected
使用 `scripts/animate.js` 简化流程:
Referenced artifact was not completely inspected
使用 `scripts/animate.js` 简化流程:
The skill instructs writing generated media to predictable filesystem locations and suggests exposing outputs via an nginx link, but does not require user confirmation, access controls, or disclosure of publication scope. In environments where generated content may contain sensitive prompts or user-derived material, this can lead to unintended data exposure or persistence of artifacts on shared systems.
While media conversion is related to video generation, the manifest specifically frames the skill as generating SVG code with a text model and composing video, without disclosing subprocess execution dependencies. Spawning host binaries is a materially broader capability than pure in-process SVG generation and may be sensitive in constrained agent environments.
This code includes natural-language comments and, more importantly, user-facing CLI help/output in Chinese, such as the usage banner and progress messages. The file does not offer an English or configurable locale option, so it imposes a specific language on users without opt-in.
The interface and manifest suggest the tool can build multi-scene story animations, but no scene segmentation, per-scene frame allocation, or story progression exists. The story text is passed directly into the same keyword classifier as theme, and scenes is parsed but never used.
The manifest describes broad text-driven generation supporting arbitrary subjects and multi-scene stories, implying the prompt meaningfully controls generated SVG content. In reality, the code just matches a few keywords and renders one of several fixed SVG generators, with all unmatched prompts defaulting to a dog animation.
The manifest advertises automatic duration calculation, but the code initializes frames to 24 and only recalculates when !frames, which never occurs under normal defaults. As a result, --duration does not drive frame computation unless frame handling is changed manually.
Detected: suspicious.dangerous_exec