Back to skill

Security audit

VSD Craft Plugin Development

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent VSD Craft plugin-development helper with disclosed scaffolding, local tests, packaging, and optional user-directed installation steps.

Install this only if you want an agent to help create, test, package, and optionally install VSD Craft or StreamDock plugins. Review generated plugin contents before installing on a real VSD Craft setup, and treat real hardware or existing-scene changes as separate user-approved steps.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This code chunk does perform packaging, which is one part of the declared description, but its actual purpose is much narrower and more restrictive than the declared skill. It does not build plugins generally, port Elgato plugins, implement SDK communication, handle input/reconnection, or provide compatibility logic. Instead, it packages only a fixed allowlisted scaffold with strict validation rules. That is a material description-versus-behavior mismatch for this supplied code chunk.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
3. For a new plugin, generate the [minimal scaffold](assets/template/plugin.js) with `python3 scripts/scaffold.py --id com.example.counter --name "Counter" --ou

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
For subsequent installs, use `npm ci` with the lockfile. The [mock-host tests](assets/template/test/smoke.cjs) use only temporary localhost ports and do not co

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
For subsequent installs, use `npm ci` with the lockfile. The [mock-host tests](assets/template/test/smoke.cjs) use only temporary localhost ports and do not co

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/test_helpers.py (reported line 46)May include surrounding context.

python
(ws / 'package.json').write_text(json.dumps({'version': '8.22.0'}))
            (root / 'package-lock.json').write_text(json.dumps({'packages': {'node_modules/ws': {'version': '8.22.0'}}}))
            (root / 'config.json').write_text('{"token":"private-fixture"}')
            (root / '.env').write_text('TOKEN=private-fixture')
            (root / 'runtime.log').write_text('private-fixture')
            output = Path(temporary) / 'plugin.zip'
            package_plugin(root, output)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/test_helpers.py (reported line 53)May include surrounding context.

python
(ws / 'package.json').write_text(json.dumps({'version': '8.22.0'}))
            (root / 'package-lock.json').write_text(json.dumps({'packages': {'node_modules/ws': {'version': '8.22.0'}}}))
            (root / 'config.json').write_text('{"token":"private-fixture"}')
            (root / '.env').write_text('TOKEN=private-fixture')
            (root / 'runtime.log').write_text('private-fixture')
            output = Path(temporary) / 'plugin.zip'
            package_plugin(root, output)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README gives activation examples like 「VSD Craft用のプラグインを作って」 and 「このElgatoプラグインをM3へ移植して」, but does not define whether these are the exact trigger phrases, examples only, or what nearby requests should not invoke the skill. For a markdown skill description, this can create ambiguous invocation boundaries and increase the chance of unintended activation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

Line L30 states that the README is 'User-facing quick start, in Japanese.' This indicates a language constraint in user-facing material, but the skill text does not mention any user choice, opt-in, or region-specific justification for requiring Japanese.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The note cites DEPLOYMENT-ja.md, indicating a Japanese-language source context, but the document does not explain whether Japanese is required or whether alternative language documentation is available. Under the language/locale policy rule, forcing or assuming a specific language without opt-in can be a policy concern when not justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The document cites README-ja.md as an original source but does not state why Japanese-language material is required or whether users have an alternative. This can imply an undocumented language constraint, which falls under the language/locale policy check.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
assets/template/test/smoke.cjs:74