Back to skill

Security audit

openshorts

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for OpenShorts video clipping and publishing, but its optional unpinned uvx CLI shortcut asks users to execute remote package code with local environment access.

Review this before installing if agents may run shell commands. Prefer the MCP or REST paths, avoid the unpinned `uvx openshorts` shortcut unless you pin and verify the package, store OpenShorts and Gemini keys only in trusted secret storage, and require explicit approval before publishing to social platforms.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:117
Finding

Unpinned Remote Package Execution Through uvx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 117-119
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

Vulnerable Code Snippet:

text
When shell access is easier than HTTP: `uvx openshorts process <url> --wait`,
`openshorts clips <job_id>`, `openshorts publish <job_id> 0 --platforms
tiktok`. Auth via `OPENSHORTS_API_KEY` / `OPENSHORTS_API_URL` env vars.

Technical Analysis

The documented uvx openshorts command can retrieve and execute the currently resolved version of the openshorts package without pinning a reviewed version or verifying package integrity. This creates a supply-chain trust boundary in which the code executed at invocation time may differ from the code reviewed when the Skill was audited.

The same instructions state that authentication is supplied through the OPENSHORTS_API_KEY environment variable. A package executed by uvx runs with the invoking user's privileges and can normally access inherited environment variables. If the package distribution, maintainer account, or dependency resolution process is compromised, malicious package code could read this API key, access local files available to the user, and execute arbitrary commands.

The remote video-processing behavior itself is disclosed and necessary for the Skill's hosted functionality. However, dynamically executing an unpinned package is not required because the Skill also supports direct REST and MCP access.

Attack Path

  1. An attacker compromises the package publisher, package registry account, or a dependency selected by an unpinned package release.
  2. The attacker publishes a malicious version that retains expected CLI behavior while adding credential theft or arbitrary command execution.
  3. A user or agent follows the Skill's documented uvx openshorts process ... shortcut.
  4. uvx resolves, downloads, and executes the malicious package version ...[truncated 791 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to an explicitly reviewed version, for example by documenting uvx openshorts==<reviewed-version> ... if the package manager supports that syntax.
  2. Use a lockfile or package-manager mechanism that verifies cryptographic hashes for the package and its transitive dependencies.
  3. Document the authoritative package registry and publisher identity so users can verify that they are installing the intended package.
  4. Prefer the documented REST or MCP interfaces where feasible, as they avoid dynamically executing a newly resolved local package.
  5. Run the CLI with the minimum necessary environment. Expose only OPENSHORTS_API_KEY when required and remove unrelated secrets from the child process.
  6. Use a restricted, short-lived, and revocable API credential where supported. Rotate the key immediately if package compromise is suspected.
  7. Consider executing the CLI in a sandbox or container with limited filesystem and network access.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · reference.md (reported line 159)May include surrounding context.

md
draft in the app; Instagram and YouTube publish directly.

Queue: `GET /api/social/scheduled`, and
`DELETE /api/social/scheduled/{job_id}` to cancel one before it goes out.

Analytics of what was published: `GET /api/social/analytics` (profile totals),
`GET /api/social/analytics/posts` (per post), and

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 14)May include surrounding context.

md
## Setup

Create an API key (`osk_...`) in your account page at
[openshorts.app](https://www.openshorts.app/) and give it to the agent the way
that host stores credentials (`OPENSHORTS_API_KEY` where an env var is the
convention). The hosted free tier includes 20 minutes of source video per month

Rp1

Medium
Category
MCP Rug Pull
Confidence
65% confidence
Finding

uvx/uv tool run commands without ==version create a rug-pull risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 57)May include surrounding context.

md
- `examples/n8n/` has the same pipeline as importable n8n workflows, including a
  daily channel autopilot with Telegram approval.
- [openshorts.app/mcp](https://www.openshorts.app/mcp) documents the MCP server,
  and [api.openshorts.app/docs](https://api.openshorts.app/docs) the full API.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · reference.md (reported line 165)May include surrounding context.

md
- `examples/n8n/` has the same pipeline as importable n8n workflows, including a
  daily channel autopilot with Telegram approval.
- [openshorts.app/mcp](https://www.openshorts.app/mcp) documents the MCP server,
  and [api.openshorts.app/docs](https://api.openshorts.app/docs) the full API.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The skill recommends running uvx openshorts without pinning an exact package version or hash, which can cause users to execute whatever release is current at install time. If the package is compromised upstream, typosquatted, or a future release introduces malicious code, the agent or user may run unreviewed code with local shell and environment access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation explicitly states that the MCP server forwards authentication headers, including API keys and Gemini keys, but does not warn users about credential sensitivity, scope, storage, or risks of sending secrets to third-party/self-hosted endpoints. In an agent/tooling context, this increases the chance of accidental secret disclosure or unsafe header forwarding across trust boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation describes posting immediately or on a schedule to TikTok, Instagram, and YouTube, plus cancellation behavior, without clearly warning that these actions have externally visible and potentially irreversible effects. In an agent skill, this can lead to unintended publication, brand damage, or user-impacting actions if invoked without explicit confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README tells users to provide an API key to the agent but does not explicitly warn that the credential is sensitive, should be scoped minimally, and must not be pasted into prompts, logs, or untrusted skill/config files. In the agent-skill context, this matters because agents may surface, store, or transmit credentials across tools, making accidental disclosure more likely.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.