Back to skill

Security audit

Veo Video Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Google Veo video generator that sends the user's prompt to Google and saves the resulting MP4 locally, with no evidence of hidden access, persistence, or data theft.

Install only if you are comfortable sending video prompts to Google GenAI and using a GEMINI_API_KEY from the environment. Review or update npm dependencies before production use because the scanner reported vulnerable transitive packages, but the skill's own behavior is coherent and disclosed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (13)

Known Vulnerable Dependency: protobufjs==7.5.4 — 12 advisory(ies): CVE-2026-44294 (protobuf.js: Denial of service from crafted field names in generated code); CVE-2026-44293 (protobuf.js: Code injection through bytes field defaults in generated toObject c); CVE-2026-44289 (protobuf.js: Denial of service through unbounded protobuf recursion) +9 more

Critical
Category
Supply Chain
Confidence
97% confidence
Finding

protobufjs 7.5.4 is reported with multiple serious issues including denial of service and possible code-injection conditions in generated-code-related paths. Because this skill depends on @google/genai, which directly pulls protobufjs, malformed remote data or untrusted schema/message handling could expose the runtime to crashes or unsafe code paths.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The code substantially aligns with the declared core purpose: it generates videos from text using Google's Veo API, requests 1080p resolution, and includes audio. However, there are notable mismatches. First, the declared triggers are empty, but the code is explicitly a CLI tool triggered via a required --prompt argument. Second, the code writes the generated video to local storage as an MP4, which is an undeclared capability/resource access. Third, the description emphasizes high-fidelity cinematic generation with Google Veo 3.1, while the implementation uses the 'veo-3.1-fast-generate-preview' model, which may be materially different from a standard high-fidelity production model. These differences are enough to flag a mismatch, though the primary purpose is mostly aligned.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
execFile('node', ['generate.js', '--prompt', userPrompt])

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
- **Shell Injection Prevention**: The user prompt **must** be passed as a discrete argument (e.g. via `execFile` or an argv array), never interpolated into a shell command string. Concatenating user input into a shell string (e.g. `shell: true` with template literals) enables shell injection and is strictly forbidden.
- **Instruction Scope**: This skill only sends text prompts to the Google GenAI API.
- **Environment**: It uses the `GEMINI_API_KEY` provided by the OpenClaw environment.
- **Data Access**: It does not read local files or .env files. All configuration is handled by the agent.

Known Vulnerable Dependency: brace-expansion==5.0.3 — 5 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-45149 (brace-expansion: Large numeric range defeats documented `max` DoS protection) +2 more

High
Category
Supply Chain
Confidence
92% confidence
Finding

brace-expansion 5.0.3 is flagged for multiple algorithmic complexity and range-expansion denial-of-service issues. Even though it is a transitive dependency, DoS in dependency processing can still be triggered if attacker-controlled patterns reach code paths using glob/minimatch behavior, which is plausible in Node ecosystems.

Content

No source excerpt is available for this finding.

Possible Typosquatting: 'gaxios' resembles popular package 'axios'

High
Category
Supply Chain
Confidence
70% confidence
Finding

Package name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.19.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
91% confidence
Finding

ws 8.19.0 is flagged for memory disclosure and memory exhaustion issues. Since this skill uses a generative media SDK that may rely on WebSocket transport for streaming or long-running operations, a vulnerable ws version is relevant and could allow denial of service or leakage under hostile network/input conditions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation rule says to activate whenever the user wants to create or render a video, which is a broad natural-language condition that can overlap with many ordinary requests. It does not provide specific trigger phrases, scope limits, or exclusion examples to clarify when this skill should or should not run.

Content

No source excerpt is available for this finding.

Indirect Prompt Extraction

Medium
Category
System Prompt Leakage
Confidence
75% confidence
Finding

Skill contains patterns that could indirectly extract system prompts through rephrasing, translation, summarization, or side-channel techniques.

Content

Scanner excerpt · generate.js (reported line 33)May include surrounding context.

js
if (SHELL_METACHAR_RE.test(userPrompt)) {
  console.error(
    "❌ Error: Prompt contains disallowed characters (; & | ` $ < > \\). " +
      "Please rephrase your prompt without shell metacharacters.",
  );
  process.exit(1);
}

Known Vulnerable Dependency: @protobufjs/utf8==1.1.0 — 1 advisory(ies): CVE-2026-44288 (protobufjs has overlong UTF-8 decoding)

Low
Category
Supply Chain
Confidence
60% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The dependency version uses a caret range (^1.0.0), which allows automatic installation of newer releases within the major version. This increases supply-chain risk because a compromised or breaking upstream release could be pulled in without explicit review, though there is no evidence of malicious intent in this package.json.

Content

Scanner excerpt · package.json (reported line 8)May include surrounding context.

json
"description": "OpenClaw skill for Google Veo 3.1 video generation.",
  "main": "generate.js",
  "dependencies": {
    "@google/genai": "^1.0.0"
  },
  "overrides": {
    "rimraf": "^6"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
84% confidence
Finding

The override for rimraf is also specified with a caret range (^6), so the resolved version may change over time. Although this is common package maintenance behavior, it still creates a low-severity supply-chain exposure by permitting unreviewed upstream updates into builds.

Content

Scanner excerpt · package.json (reported line 11)May include surrounding context.

json
"@google/genai": "^1.0.0"
  },
  "overrides": {
    "rimraf": "^6"
  },
  "engines": {
    "node": ">=20.0.0"

Static analysis

No suspicious patterns detected.