Back to skill

Security audit

Video Download Transcribe

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its video-download and transcription purpose, but it needs Review because broad URL triggers can lead to external processing of video URLs, transcripts, and frames without clear consent or data controls.

Review this carefully before installing. Use it only for videos you are comfortable sending to third-party services, avoid private or tokenized URLs, and prefer an isolated environment with pinned dependencies or a verified release. The publisher should narrow automatic triggers, add an explicit consent step before remote processing, document providers and retention, and ship or pin the referenced implementation files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:160
Finding

Unrestricted Transmission of User Content to External Services

Content
View full analysis
" ``` ```bash # Obtain video information and a playback URL through a remote authenticated service mcporter call tikhub-douyin.douyin_web_fetch_one_video_by_share_url share_url:"" # Obtain the highest-quality CDN address mcporter call tikhub-douyin.douyin_web_fetch_video_high_quality_play_url share_url:"" ``` The visual-analysis workflow additionally specifies that: - The complete transcript is sent to an LLM to identify visually relevant points. - Extracted video frames are sent to MiniMax for image analysis. - The combined transcript and frame analysis are sent to an LLM for final synthesis. ### Technical Analysis The Skill supports local transcription, but its enhanced workflow forwards several classes of potentially sensitive data to remote services: 1. User-provided video URLs are sent to TikHub. 2. Complete transcripts are sent to an unspecified LLM. 3. Extracted frames are sent to MiniMax. 4. Combined audio and visual information is sent to an LLM for synthesis. A private or unlisted video URL may contain access tokens, signed query parameters, account identifiers, or resource identifiers. Transcripts may include personal conversations, confidential business information, credentials spoken aloud, or regulated data. Frames may expose faces, private documents, source code, terminal output, authentication data, or other on-screen content. Remote processing is relev ...[truncated 2567 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:127
Finding

Unpinned Dependencies and Browser Binaries from Mutable External Sources

Content
View full analysis
/dev/null || true PLAYWRIGHT_DOWNLOAD_HOST=https://npmmirror.com/mirrors/playwright \ ~/openclaw-media/.venv/bin/playwright install chromium pip install playwright PLAYWRIGHT_DOWNLOAD_HOST=https://npmmirror.com/mirrors/playwright playwright install chromium ``` The troubleshooting instructions repeat the browser download through the same mirror: ```bash PLAYWRIGHT_DOWNLOAD_HOST=https://npmmirror.com/mirrors/playwright \ ~/openclaw-media/.venv/bin/playwright install chromium ``` ### Technical Analysis The installation workflow obtains executable code and browser binaries from mutable external sources without pinning or integrity verification: - The Git repository is cloned without a commit hash, tag, or signed-release requirement. - `pip install playwright` does not specify an exact version or verify a locked dependency set. - Chromium is downloaded through `npmmirror.com` without a checksum or signature check. - The instructions rely on executable tooling from the newly cloned repository. - Suppressing Git error output and forcing success with `2>/dev/null || true` can obscure a failed or partial clone and make the resulting state harder to validate. Because these sources are mutable, the code and binaries installed in the future may differ from those reviewed when the Skill was published. A compromise of the repository, package account, package index, mirror, DNS path, or artifact publication process could cause attacker-controlled code to execute during installation or later browser automation. The available evidence does not establish that the current repository, Playwright package, or mirror artifact is malicious. The vulnerability is t ...[truncated 1743 chars]
Remediation
View remediation
/dev/null || true`. - Stop installation when cloning or verification fails. - Report the resolved commit, package version, browser revision, source URL, and checksum. 6. Apply least privilege: - Never recommend running these installation commands as root. - Install into an isolated virtual environment or container. - Restrict access to unrelated home-directory files and secrets during browser automation. ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language description, triggers, and usage guidance are entirely specified in Chinese, including the activation phrases, with no indication that other languages are supported or that Chinese is an explicit opt-in requirement. This can violate language/locale policy when a skill implicitly requires a specific language without user choice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is configured to trigger on very broad everyday phrases such as asking what a video says or simply sending a supported URL, which can cause unintended invocation during normal conversation. Because the skill downloads remote content and may invoke external tools and networked services, accidental triggering can lead to unwanted processing of user data, unexpected network access, and surprise execution of potentially costly or privacy-impacting actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.