T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/new-project.py:31- Finding
Unrestricted project destination permits writes outside the workspace
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This video-generation skill is mostly purpose-aligned, but its helper scripts and dependency setup can affect more of the filesystem and network supply chain than its own permissions describe.
Review this before installing. Use only simple relative project names and project-local output paths, do not enable recurring cron renders unless the schedule, output folder, retention, and removal method are explicit, and consider pinning dependencies with a lockfile before running npm install or rendering.
scripts/new-project.py:31Unrestricted project destination permits writes outside the workspace
scripts/render.py:20Unrestricted render output path permits writes and overwrites outside the project
assets/boilerplate/package.json:5Mutable dependencies and implicit npx installation make execution non-reproducible
Without declared permissions the skill's intent is opaque and cannot be validated.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## Anti-Patterns (Don't Do This)
❌ "I'm going to make a video for you" — never auto-generate without asking
❌ Re-offering after a "no" on the same content
❌ Suggesting video for text that is clearly meant to stay text (code, config, email draft)
❌ Overwhelming with options: "I can do 5 different templates!" — pick the best one, offer one
The file provides recurring cron-based automation examples but omits the explicit consent safeguards required by the skill metadata: confirming schedule, output directory, file retention policy, and a disable method before creating any cron job. In an agentic system that can run shell commands, this gap can lead to unauthorized or insufficiently understood background automation, causing repeated file generation and persistence beyond user intent.
The recurring guidance says to 'Set up cron jobs for recurring video creation' and lists trigger/action pairs without the mandatory step of asking the user and obtaining the required confirmations first. That contradicts the skill's stated permission boundary and increases the chance an agent will treat recurring execution as routine rather than opt-in, enabling ongoing automated actions the user did not fully approve.
The automation section describes recurring video generation without warning users that their content may be processed repeatedly and that automated jobs will continue running until disabled. Even without networking or external file access, repeated use of workspace content and ongoing renders can surprise users, consume resources, and retain derivative outputs longer than expected.
The script joins the user-supplied project name directly with the current working directory, so names containing path traversal sequences or absolute paths can cause files to be created outside the intended project directory boundary. In this skill, the ability to scaffold and write many files makes boundary bypass more significant because it could overwrite or plant project content elsewhere in the workspace despite the manifest claiming writes are constrained.
Using npx remotion without pinning a specific version can cause execution of whatever package version is resolved at runtime, which may differ across environments or unexpectedly pull newer code. In a skill that is allowed to run Node/npm shell commands, this increases supply-chain risk and weakens reproducibility, especially if package resolution is not tightly controlled.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
cmd += ["--concurrency", str(args.concurrency)]
print("Running:", " ".join(cmd))
result = subprocess.run(cmd)
sys.exit(result.returncode)
The manifest's permission boundaries state 'No networking', which sets an expectation that the skill stays local to the workspace. SKILL.md includes a direct external GitHub release link for the showcase video, which introduces network access outside the declared boundary.
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"version": "1.0.0",
"private": true,
"dependencies": {
"@remotion/cli": "^4.0.0",
"@remotion/tailwind-v4": "^4.0.0",
"react": "^19.0.0",
"react-dom": "^19.0.0",
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"private": true,
"dependencies": {
"@remotion/cli": "^4.0.0",
"@remotion/tailwind-v4": "^4.0.0",
"react": "^19.0.0",
"react-dom": "^19.0.0",
"remotion": "^4.0.0",
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"dependencies": {
"@remotion/cli": "^4.0.0",
"@remotion/tailwind-v4": "^4.0.0",
"react": "^19.0.0",
"react-dom": "^19.0.0",
"remotion": "^4.0.0",
"tailwindcss": "^4.0.0"
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"@remotion/cli": "^4.0.0",
"@remotion/tailwind-v4": "^4.0.0",
"react": "^19.0.0",
"react-dom": "^19.0.0",
"remotion": "^4.0.0",
"tailwindcss": "^4.0.0"
},
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"@remotion/tailwind-v4": "^4.0.0",
"react": "^19.0.0",
"react-dom": "^19.0.0",
"remotion": "^4.0.0",
"tailwindcss": "^4.0.0"
},
"devDependencies": {
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"react": "^19.0.0",
"react-dom": "^19.0.0",
"remotion": "^4.0.0",
"tailwindcss": "^4.0.0"
},
"devDependencies": {
"@types/react": "^19.0.0",
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"tailwindcss": "^4.0.0"
},
"devDependencies": {
"@types/react": "^19.0.0",
"@types/web": "^0.0.166",
"typescript": "^5.5.0"
},
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
},
"devDependencies": {
"@types/react": "^19.0.0",
"@types/web": "^0.0.166",
"typescript": "^5.5.0"
},
"scripts": {
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"devDependencies": {
"@types/react": "^19.0.0",
"@types/web": "^0.0.166",
"typescript": "^5.5.0"
},
"scripts": {
"dev": "remotion studio",
No suspicious patterns detected.