Back to skill

Security audit

NovaVideo

Security checks for vulnerabilities and agentic risk

Overview

This media-generation skill is mostly coherent, but it needs Review because installation delegates control to mutable remote instructions and credentialed requests use an unvalidated configurable endpoint.

Install only if you are comfortable with prompts and reference images being sent to Nova Video. Do not use sensitive, private, or proprietary media without consent, avoid following mutable remote SKILL.md instructions as an install method, and ensure NOVA_BASE_URL points only to the intended HTTPS Nova endpoint before using your API key.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:15
Finding

Installation Delegates Agent Control to Mutable Remote Instructions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:38
Finding

Bearer API Credential Can Be Sent to an Unvalidated Configurable Endpoint

Content
View full analysis
", "size": "2k" }' ``` The same configurable base URL and bearer-token combination is used by the image-generation, video-generation, status-polling, and history-listing examples. The API also permits reference images to be submitted as public URLs or base64 data: ```markdown > `imageUrl` accepts two formats: > - A publicly accessible image URL, e.g. `https://example.com/photo.jpg` > - A base64-encoded image, e.g. `data:image/jpeg;base64,/9j/4AAQ...` ``` ### Technical Analysis `NOVA_BASE_URL` determines the destination receiving the `Authorization: Bearer $NOVA_API_KEY` header. The documented requests do not validate that this variable resolves to the intended HTTPS origin before transmitting the credential. If the environment variable is already set, is altered by another process or setup script, or is copied from untrusted instructions, the requests can be directed to an attacker-controlled server. That server would receive the bearer token and request body. Depending on the operation, the body may contain user prompts, generated-image URLs, motion descriptions, or base64-encoded reference images. Sending an API credential and generation input to the declared Nova service is necessary for t ...[truncated 1724 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

  1. Return the imageUrl from the response
bash
curl -s -X POST "$NOVA_BASE_URL/api/openapi/image" \
  -H "Authorization: Bearer $NOVA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

Step 3 — Submit video task

bash
VIDEO_RESP=$(curl -s -X POST "$NOVA_BASE_URL/api/openapi/video" \
  -H "Authorization: Bearer $NOVA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 300)May include surrounding context.

"Generate a cyberpunk-style cityscape at night"

bash
curl -s -X POST "$NOVA_BASE_URL/api/openapi/image" \
  -H "Authorization: Bearer $NOVA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"prompt": "Cyberpunk cityscape at night, neon reflections on rain-soaked streets, cinematic quality", "size": "2k"}'

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 321)May include surrounding context.

md
echo "Reference image: $IMAGE_URL"

# Step 2: Submit video task with motion prompt
TASK=$(curl -s -X POST "$NOVA_BASE_URL/api/openapi/video" \
  -H "Authorization: Bearer $NOVA_API_KEY" \
  -H "Content-Type: application/json" \
  -d "{\"prompt\": \"Slow aerial drone flyover, golden sunrise light filtering through treetops, morning mist drifting through valleys, gentle camera push forward, cinematic\", \"imageUrl\": \"$IMAGE_URL\", \"duration\": 4, \"aspectRatio\": \"16:9\", \"resolution\": \"720p\"}")

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 334)May include surrounding context.

md
ATTEMPT=0
while [ $ATTEMPT -lt $MAX_ATTEMPTS ]; do
  ATTEMPT=$((ATTEMPT + 1))
  STATUS=$(curl -s "$NOVA_BASE_URL/api/openapi/video?taskId=$TASK_ID" \
    -H "Authorization: Bearer $NOVA_API_KEY")
  STATE=$(echo $STATUS | python3 -c "import sys,json; print(json.load(sys.stdin)['data']['status'])")
  echo "[$ATTEMPT/$MAX_ATTEMPTS] Status: $STATE"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough that the skill may activate on loosely related requests, causing users' prompts or referenced URLs to be sent to an external service without clear intent. In an agent ecosystem, overbroad activation increases the chance of unintended third-party data disclosure and surprising tool behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill markets simple image/video generation but does not prominently warn that user prompts and referenced image URLs are transmitted to an external API endpoint. This can lead to inadvertent disclosure of sensitive prompts, proprietary media URLs, or personal data to a third party without informed consent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This workflow transmits the user's free-form prompt to an external API using an authorization-bearing request. That is expected for the skill's function, but it is still a real data-transfer risk because prompts may contain sensitive or proprietary information and the skill does not require explicit per-request consent.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

  1. Return the imageUrl from the response
bash
curl -s -X POST "$NOVA_BASE_URL/api/openapi/image" \
  -H "Authorization: Bearer $NOVA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

The video submission step sends a derived motion prompt and reference image URL or base64 image to a third-party API. This expands the exposure surface beyond text prompts to potentially sensitive media content, making unintended disclosure more consequential.

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

Step 3 — Submit video task

bash
VIDEO_RESP=$(curl -s -X POST "$NOVA_BASE_URL/api/openapi/video" \
  -H "Authorization: Bearer $NOVA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

A default locale of zh without user opt-in can cause unintended data handling or content generation behavior inconsistent with the user's expectations. While not a direct exploit vector, silent defaults that alter external processing can create privacy, compliance, or output-integrity concerns.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 300)May include surrounding context.

"Generate a cyberpunk-style cityscape at night"

bash
curl -s -X POST "$NOVA_BASE_URL/api/openapi/image" \
  -H "Authorization: Bearer $NOVA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"prompt": "Cyberpunk cityscape at night, neon reflections on rain-soaked streets, cinematic quality", "size": "2k"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 321)May include surrounding context.

md
echo "Reference image: $IMAGE_URL"

# Step 2: Submit video task with motion prompt
TASK=$(curl -s -X POST "$NOVA_BASE_URL/api/openapi/video" \
  -H "Authorization: Bearer $NOVA_API_KEY" \
  -H "Content-Type: application/json" \
  -d "{\"prompt\": \"Slow aerial drone flyover, golden sunrise light filtering through treetops, morning mist drifting through valleys, gentle camera push forward, cinematic\", \"imageUrl\": \"$IMAGE_URL\", \"duration\": 4, \"aspectRatio\": \"16:9\", \"resolution\": \"720p\"}")

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 360)May include surrounding context.

md
echo "Reference image: $IMAGE_URL"

# Step 2: Submit video task with motion prompt
TASK=$(curl -s -X POST "$NOVA_BASE_URL/api/openapi/video" \
  -H "Authorization: Bearer $NOVA_API_KEY" \
  -H "Content-Type: application/json" \
  -d "{\"prompt\": \"Slow aerial drone flyover, golden sunrise light filtering through treetops, morning mist drifting through valleys, gentle camera push forward, cinematic\", \"imageUrl\": \"$IMAGE_URL\", \"duration\": 4, \"aspectRatio\": \"16:9\", \"resolution\": \"720p\"}")

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes a media-generation skill for creating images/videos and checking or listing generations, but this section adds filesystem write behavior by instructing the agent to save the full video URL into video_url.txt. Writing local files is not mentioned in the stated skill purpose and goes beyond the described user-facing operations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.