Back to skill

Security audit

previs-rerender

Security checks for vulnerabilities and agentic risk

Overview

This skill is a clearly scoped Ofox video workflow that discloses its API key, public-video URL, paid generation, and approval requirements.

Before installing, verify that you trust the Ofox skill source and the separate `ofox-video-core` dependency, provide an `OFOX_API_KEY` only through the environment, use only video URLs you are authorized to transform, and review the dry-run quote before approving any paid generation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: previs-rerender
description: Requires OFOX_API_KEY — create one at https://app.ofox.ai, plus a publicly reachable reference video the user is authorized to use. Use when a user has a rough 3D white-model, clay, wireframe, blockout, previs, or animatic clip and wants a finished visual treatment that preserves its shot order, cut timing, camera framing, spatial layout, and motion directions. Distinguishes that structure-preserving job from a continuation beginning at the reference's final state. Do not use for two still endpoints (keyframe-animation), for appending and locally joining a new ending (video-extend-edit), or when still-image references must be combined with the video in one request — first/last-frame anchors conflict with video references in the shipped core, while mixed image/video references are untested.
license: MIT
version: "1.0.0"
homepage: https://github.com/ofoxai/skills/tree/main/skills/previs-rerender

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The skill instructs use of npx skills add ... without pinning an exact package version or immutable source. That creates a supply-chain risk: a future or compromised package release could execute unintended code during installation, especially since users are told to run it as a remediation path when the dependency is missing.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

md
- **For continuation:** what must happen after the final state, what earlier
  material must not replay, and where the new segment should settle.

Do not ask the user to redescribe camera moves already legible in the previs.
Do name the structural cues that will be checked afterward: shot count and
order, cut times, framing or layout per shot, and each important motion
direction.

Static analysis

No suspicious patterns detected.