Back to skill

Security audit

Agent Media: Generate AI-powered videos and images from the terminal using the `agent-media` CLI.

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward guide for using an external video-generation CLI, with some normal but important privacy and supply-chain considerations.

Before installing, verify the npm package and consider using a contained environment. Expect the CLI to authenticate with an external service and upload media you provide, including screenshots, face photos, voice samples, and video files. Ask the agent to get permission before browsing product URLs or using third-party images.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:72
Finding

Unpinned Global Installation and Execution of an Unaudited Third-Party Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 72-79
Vulnerability Type: Unpinned and globally installed third-party dependency
Risk Level: Medium

Vulnerable Code Snippet

markdown
## Prerequisites

The `agent-media` CLI must be installed and authenticated:

```bash
npm install -g agent-media-cli
agent-media login
text

### Technical Analysis

The skill instructs users to install `agent-media-cli` globally from the npm registry without specifying an exact version or verifying its integrity or provenance. The dependency's source code is not included in the audited project, so its installation scripts and runtime behavior cannot be verified from the available artifact.

An npm package can execute lifecycle scripts during installation. A global installation also places an executable on the system path and runs installation behavior with the permissions of the invoking user. Because no version or integrity digest is pinned, the effective code installed by this command can change after the skill has been reviewed.

This is a supply-chain security weakness rather than evidence that the referenced package is presently malicious.

### Attack Path

1. An attacker compromises the npm publisher account, package release process, or another component of the package's supply chain.
2. The attacker publishes a malicious or backdoored version under the existing `agent-media-cli` package name.
3. A user follows the skill instructions and runs `npm install -g agent-media-cli`.
4. npm retrieves the current package release without enforcing an audited version or integrity value.
5. Malicious package lifecycle scripts can execute during installation, or malicious behavior can run when the user invokes `agent-media login` or subsequent media commands.
6. The package operates with the invoking user's privileges and can potentially access files, environment variables, authentication material, and data supplied to the CLI.

### Impact Assessment

Suc
...[truncated 817 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to an explicitly reviewed version instead of installing the latest release implicitly:

    bash
    npm install --global agent-media-cli@<reviewed-version>
    
  2. Record and verify the expected package integrity digest and publisher provenance before installation. Use npm provenance information and require releases produced through a trusted, auditable build process.

  3. Avoid global installation where possible. Install the dependency in a dedicated project with a committed lockfile, or run it in an isolated container or restricted environment.

  4. Audit the exact package version, including its transitive dependencies and npm lifecycle scripts, before recommending it.

  5. Disable npm lifecycle scripts during installation when they are not required:

    bash
    npm install --ignore-scripts agent-media-cli@<reviewed-version>
    

    If lifecycle scripts are necessary, review them explicitly before allowing execution.

  6. Execute the CLI under a least-privileged account with access limited to the media files required for the task. Do not expose unrelated credential directories, SSH keys, cloud credentials, or sensitive environment variables.

  7. Clearly disclose that local screenshots, voice samples, face photographs, and other media may be uploaded to an external service. Obtain user authorization before transmitting such data and document the destination, retention policy, and deletion process.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly instructs the agent to visit arbitrary product websites and extract image URLs when the user has not provided screenshots. That expands the skill from local CLI-driven media generation into network browsing and scraping of third-party content, which can trigger unintended outbound requests, collect more data than the user expected, and bypass normal consent boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill directs the agent to access product websites and extract image URLs without warning the user that network access will occur or that third-party resources may be collected and reused. This is dangerous because it undermines transparency and can surprise users with external requests, possible logging/tracking by visited sites, and handling of content they did not explicitly authorize the agent to fetch.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prescribed SaaS review workflow tells the agent to stop and then visit a site to extract dashboard/UI image URLs if screenshots are missing. This creates a concrete, repeatable browsing/scraping behavior beyond the stated terminal video-production purpose, increasing the risk of unauthorized external access and use of third-party assets without explicit user approval.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.