Back to skill

Security audit

Social Video Distill

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent video-summary purpose, but it uses an authenticated browser AI session, arbitrary browser/app endpoints, unvalidated media URLs, and mutable dependency installs with weak disclosure and scoping.

Review before installing. Use only with public or non-sensitive clips unless you are comfortable sending transcripts, notes, and prompts to Gemini or NotebookLM. Run browser automation in a dedicated local browser profile, avoid remote CDP endpoints and custom app URLs, avoid private/internal media URLs, and consider pinning dependencies and cleaning downloaded files after use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
scripts/install_runtime.sh:10
Finding

Unpinned Runtime Dependencies Permit Mutable Supply-Chain Code

Content
View full analysis
/dev/null 2>&1) fi (cd "$NODE_DIR" && npm install --silent puppeteer-core@24) ``` ### Technical Analysis The installer dynamically retrieves `pip`, `yt-dlp`, and `puppeteer-core` from external package registries. Neither the Python packages nor `pip` are version-pinned. The Puppeteer dependency is constrained only to major version 24 rather than an exact reviewed release. No lockfile, integrity hash, or package-signature verification is used. As a result, the code installed by this script can change without any corresponding change to the audited project. A compromised package registry, compromised maintainer account, malicious package release, or unexpectedly incompatible update could introduce code that was not present during review. This finding concerns unsafe dependency resolution rather than evidence that the currently named packages are malicious. ### Attack Path 1. An attacker compromises a relevant registry account or publishes a malicious release within the accepted version range. 2. A user follows the documented setup process and runs `scripts/install_runtime.sh`. 3. `pip` or `npm` resolves the mutable dependency to the attacker-controlled release. 4. The package is installed into the skill runtime. 5. Malicious package behavior executes during installation or when `yt-dlp` or Puppeteer is later loaded and invoked. ### Impact Assessment Malicious dependency code would generally execute with the privileges of the user running the installer or skill. It could access files readable by that user, make network requests, alte ...[truncated 305 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/download_media.sh:8
Finding

Unrestricted Media URL Processing Can Enable Server-Side Request Forgery

Content
View full analysis
&2 echo "Run: bash $SKILL_DIR/scripts/install_runtime.sh" >&2 exit 1 fi mkdir -p "$OUTDIR" "$YT_DLP" -o "$OUTDIR/%(id)s.%(ext)s" "$URL" ``` From `scripts/extract_captions.sh`: ```bash URL="$1" OUTDIR="${2:-$(pwd)/tmp/social-video-distill-captions}" SKILL_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)" YT_DLP="$SKILL_DIR/.runtime/ytvenv/bin/yt-dlp" if [[ ! -x "$YT_DLP" ]]; then echo "INSTALL_RUNTIME_REQUIRED" >&2 echo "Run: bash $SKILL_DIR/scripts/install_runtime.sh" >&2 exit 1 fi mkdir -p "$OUTDIR" BEFORE_COUNT="$(find "$OUTDIR" -maxdepth 1 -type f | wc -l)" "$YT_DLP" \ --skip-download \ --write-subs \ --write-auto-subs \ --sub-langs 'all,-live_chat' \ --convert-subs srt \ -o "$OUTDIR/%(id)s.%(ext)s" \ "$URL" ``` ### Technical Analysis Both scripts accept the first command-line argument as a URL and pass it directly to `yt-dlp`. They do not restrict the scheme or hostname, resolve and reject non-public addresses, validate redirect destinations, or enforce the documented set of public social-video platforms. Shell command injection is mitigated because the URL is correctly quoted and is not evaluated as shell syntax. However, quoting does not prevent the invoked network client from contacting attacker-selected endpoints. In an agent or server environment, this creates an SSRF-style primitive whose exact reach depends on the protocols and URL forms supported by the installed `yt-dlp` versi ...[truncated 998 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ask_gemini_cdp.js:12
Finding

Unrestricted Application URL Can Exfiltrate Prompt Data Through the Browser Session

Content
View full analysis
setTimeout(r, 4000)); const initial = await bodyText(page); if (/Sign in|登入|登录/.test(initial) && !/Gemini/.test(initial)) { console.log('GEMINI_NOT_LOGGED_IN'); await page.close(); await browser.disconnect(); process.exit(1); } const input = await findInput(page); if (!input) { console.log('INPUT_NOT_FOUND'); console.log(initial.slice(0, 4000)); await page.close(); await browser.disconnect(); process.exit(1); } await page.click(input.sel); await page.keyboard.type(prompt, { delay: 1 }); await page.keyboard.press('Enter'); ``` The input search is generic: ```javascript const selectors = [ 'div[contenteditable="true"]', 'textarea', '[role="textbox"]', 'rich-textarea div[contenteditable="true"]' ]; ``` ### Technical Analysis The `--app-url` argument can direct the automated page to any origin. The script then searches for common editable elements and types the full prompt into the first matching element before pressing Enter. It does not require the final page origin to be `https://gemini.google.com`, validate redirects, or establish a Gemini-specific page identity before disclosing the prompt. A malicious page can easily expose a matching `textarea`, content-editable element, or textbox role. If an attacker can influence invocation arguments, promp ...[truncated 1694 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill metadata and instructions present a broad media-distillation workflow, but the described behavior relies on browser automation to submit arbitrary prompts to Gemini and assumes an authenticated external session. That mismatch can mislead operators about what data leaves the local environment and what capabilities are actually implemented, increasing the risk of unintended external disclosure or unsafe execution paths.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs users to send transcripts or clip-derived content to browser AI services without any explicit warning that this content may be transmitted to third-party systems. Even if the videos are public, transcripts, notes, and user-supplied context may contain sensitive information or create compliance issues when uploaded without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow recommends downloading media and using browser AI, but it does not disclose local file effects, storage location, or the privacy implications of processing downloaded content with external services. This can lead to silent retention of media on disk and unintentional sharing of content beyond the user's expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script accepts an arbitrary --browser-url and then attaches to that Chrome DevTools endpoint with Puppeteer, which grants powerful control over the connected browser context. If an attacker can influence this parameter, they could steer the script to a remote or sensitive browser session and exfiltrate page contents, cookies via browser actions, or interact with unrelated authenticated sites.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes a skill focused on distilling shared social-video content, with browser AI like Gemini used as one step in that workflow after obtaining video/caption inputs. This file instead implements a generic browser-automation client for submitting arbitrary prompts to Gemini and scraping the page response, with no code tying the prompt to social-video URLs, transcripts, captions, or media distillation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

User-supplied prompt content is typed directly into Gemini and submitted without any disclosure, consent checkpoint, or filtering. In this skill context, users may provide transcripts, local clip content, or other sensitive material, so the script can silently transmit private data to a third-party service contrary to user expectations or policy requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script automatically creates a Python virtual environment and installs packages from external registries (pip install yt-dlp and npm install puppeteer-core) without any user-facing disclosure, consent, or integrity verification. This is risky because installation triggers network access and executes package-install logic from third-party ecosystems, increasing supply-chain and unexpected runtime-change exposure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.