Back to skill

Security audit

Video Subtitles

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to do the advertised subtitle work, but it can automatically install changing dependencies and overwrite files without confirmation, so it needs review before use.

Review this before installing. Run it only on media files and output paths you choose, avoid pointing -o at existing important files, and prefer running it in a constrained environment. The publisher should pin dependencies, use secure temporary files, and require an explicit overwrite option.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
scripts/generate_srt.py:1
Finding

Unpinned Runtime Dependency Creates a Supply-Chain Risk

Content
View full analysis
=3.10" # dependencies = [ # "faster-whisper>=1.0.0", # ] # /// ``` ### Technical Analysis The script is executed through `uv run` and declares `faster-whisper>=1.0.0` as an inline dependency. This open-ended constraint permits any current or future version satisfying the minimum version requirement. No exact version, lockfile, package hash, or other integrity control is present in the audited project. Consequently, the dependency content used by the script can change after the Skill has been reviewed. If the package distribution or an upstream dependency is compromised, a later invocation could install and import attacker-controlled code. This finding concerns unsafe dependency resolution. The audit found no evidence that the currently named package is intentionally malicious. ### Attack Path 1. An attacker compromises a future release of `faster-whisper`, its package-distribution account, its repository pipeline, or a transitively resolved dependency. 2. The malicious release remains compatible with the declared `>=1.0.0` constraint. 3. A user invokes `scripts/generate_srt.py` through its `uv run` shebang in an environment that does not already have a securely locked dependency set. 4. `uv` resolves and installs the compromised compatible release. 5. The script imports the package using: ```python from faster_whisper import WhisperModel ``` 6. Malicious package initialization or runtime code executes with the permissions of the user running the Skill. ### Impact Assessment Successful exploitation could provide arbitrary code execution under the invoking user's account. The resulting access would be limited by that user's operating-system per ...[truncated 567 chars]
Remediation
View remediation
", # ] ``` 2. Maintain a lockfile containing exact versions for the complete transitive dependency graph. 3. Use package hashes or another integrity-verification mechanism where supported. 4. Resolve and install dependencies during a controlled setup or build phase rather than silently selecting new releases whenever the script is launched. 5. Periodically update the pinned dependency through a review process that includes vulnerability scanning and release provenance verification. 6. Use a trusted package index and prevent unintended fallback to untrusted or user-controlled indexes. 7. Run transcription in a sandbox with restricted filesystem and network access to reduce the impact of a future supply-chain compromise. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_srt.py:184
Finding

Predictable Temporary Subtitle File Allows Symlink-Based File Overwrite

Content
View full analysis
/path/writable/by/victim ``` 3. The victim runs the Skill with `--srt --embed` or `--srt --burn`. 4. `embed_subtitles` opens `/tmp/subtitles_temp.srt` using write mode. 5. The operating system follows the attacker's symbolic link. 6. The linked target is truncated and replaced with generated SRT content under the victim's authority. 7. ...[truncated 1200 chars]
Remediation
View remediation
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises shell execution and file-writing behavior through commands like running local scripts and producing output files, but it declares no explicit tool scope or permissions. This creates an authorization gap: an agent may be allowed to execute filesystem and shell-capable actions implicitly, making it harder to enforce least privilege and increasing the risk of unintended command execution or file modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script forces overwrites by passing -y to ffmpeg and also writes output files directly without any confirmation, which can destroy existing user data if the output path collides with an important file. In an agent/automation context this is more dangerous because file paths may be generated or supplied programmatically, making accidental clobbering more likely and less visible to the user.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/generate_srt.py (reported line 221)May include surrounding context.

python
output_path
            ]
        
        result = subprocess.run(cmd, capture_output=True, text=True)
        if result.returncode != 0:
            print(f"ffmpeg error: {result.stderr}", file=sys.stderr)
            raise RuntimeError("ffmpeg failed")

Static analysis

No suspicious patterns detected.