Back to skill

Security audit

SVG Animator

Security checks for vulnerabilities and agentic risk

Overview

The skill is a mostly coherent SVG-to-video helper, but it has a confirmed unsafe command-execution path and overstates what it can generate.

Install only if you are comfortable with local command execution and generated files under /tmp. Do not pass output paths from untrusted users or automation until the script replaces shell-based execSync calls with argument-array execution and validates output locations. Treat the advertised generation features as limited templates rather than general LLM video generation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/animate.js:258
Finding

OS Command Injection Through the User-Controlled Output Path

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description materially overstates and misrepresents the code. The code is a deterministic template renderer: it inspects the theme/story text for a few keywords and selects one of several predefined SVG generators. There is no LLM usage at all, despite the description centering on 'using text LLM' to generate SVG. The claim of supporting 'any subject' is inaccurate because unsupported inputs fall back to a default running dog. The --story and --scenes options do not create multiple scenes or story structure; the code simply passes story text into the same single-theme frame generator and never uses scenes. Duration handling is also only partially implemented because frames is initialized to 24, so the conditional recalculation from duration rarely applies. While the code genuinely does synthesize SVG frames into a video via rsvg-convert and ffmpeg, the declared purpose does not accurately represent the actual scope or mechanism.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 262)May include surrounding context.

md
使用 `scripts/animate.js` 简化流程:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 266)May include surrounding context.

md
使用 `scripts/animate.js` 简化流程:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 269)May include surrounding context.

md
使用 `scripts/animate.js` 简化流程:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 272)May include surrounding context.

md
使用 `scripts/animate.js` 简化流程:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs writing generated media to predictable filesystem locations and suggests exposing outputs via an nginx link, but does not require user confirmation, access controls, or disclosure of publication scope. In environments where generated content may contain sensitive prompts or user-derived material, this can lead to unintended data exposure or persistence of artifacts on shared systems.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

While media conversion is related to video generation, the manifest specifically frames the skill as generating SVG code with a text model and composing video, without disclosing subprocess execution dependencies. Spawning host binaries is a materially broader capability than pure in-process SVG generation and may be sensitive in constrained agent environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code includes natural-language comments and, more importantly, user-facing CLI help/output in Chinese, such as the usage banner and progress messages. The file does not offer an English or configurable locale option, so it imposes a specific language on users without opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The interface and manifest suggest the tool can build multi-scene story animations, but no scene segmentation, per-scene frame allocation, or story progression exists. The story text is passed directly into the same keyword classifier as theme, and scenes is parsed but never used.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes broad text-driven generation supporting arbitrary subjects and multi-scene stories, implying the prompt meaningfully controls generated SVG content. In reality, the code just matches a few keywords and renders one of several fixed SVG generators, with all unmatched prompts defaulting to a dog animation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest advertises automatic duration calculation, but the code initializes frames to 24 and only recalculates when !frames, which never occurs under normal defaults. As a result, --duration does not drive frame computation unless frame handling is changed manually.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/animate.js:254