Back to skill

Security audit

Cinematic Script Writer

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent cinematic script-writing skill with expected memory, Google Drive, and local export behavior, but it has packaging and dependency hygiene issues users should review.

Install only if you are comfortable with a Node/npm skill that can store story project state, call Google OAuth/Drive APIs when you connect Drive, and write exported project files to local storage when configured. Prefer running it in a normal workspace, review Google Drive permissions during OAuth, and update development dependencies before using this repository for development or CI.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
examples/file-manager-skill/index.ts:38
Finding

Base-directory containment bypass permits unauthorized filesystem access

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (94)

Known Vulnerable Dependency: handlebars==4.7.8 — 8 advisory(ies): CVE-2026-33916 (Handlebars.js has Prototype Pollution Leading to XSS through Partial Template In); CVE-2026-33937 (Handlebars.js has JavaScript Injection via AST Type Confusion); CVE-2026-33938 (Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @part) +5 more

Critical
Category
Supply Chain
Confidence
97% confidence
Finding

handlebars 4.7.8 has multiple serious issues including prototype pollution and possible code or script injection through template compilation pathways. Even though this is a dev dependency via ts-jest rather than an obvious runtime dependency, the severity is higher because template engines become dangerous quickly if any untrusted template content reaches build or test tooling.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This mismatch appears to overstate the skill's capabilities rather than hide a more dangerous implementation: if the package is mainly a cinematography reference API and lacks claimed script writing, voice, anachronism, and Drive features, it is still a trust and integrity problem. Users may grant installation or permissions expecting one behavior while receiving another, which undermines informed consent and safe review.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This mismatch appears to overstate the skill's capabilities rather than hide a more dangerous implementation: if the package is mainly a cinematography reference API and lacks claimed script writing, voice, anachronism, and Drive features, it is still a trust and integrity problem. Users may grant installation or permissions expecting one behavior while receiving another, which undermines informed consent and safe review.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This mismatch appears to overstate the skill's capabilities rather than hide a more dangerous implementation: if the package is mainly a cinematography reference API and lacks claimed script writing, voice, anachronism, and Drive features, it is still a trust and integrity problem. Users may grant installation or permissions expecting one behavior while receiving another, which undermines informed consent and safe review.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This mismatch appears to overstate the skill's capabilities rather than hide a more dangerous implementation: if the package is mainly a cinematography reference API and lacks claimed script writing, voice, anachronism, and Drive features, it is still a trust and integrity problem. Users may grant installation or permissions expecting one behavior while receiving another, which undermines informed consent and safe review.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This mismatch appears to overstate the skill's capabilities rather than hide a more dangerous implementation: if the package is mainly a cinematography reference API and lacks claimed script writing, voice, anachronism, and Drive features, it is still a trust and integrity problem. Users may grant installation or permissions expecting one behavior while receiving another, which undermines informed consent and safe review.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This mismatch appears to overstate the skill's capabilities rather than hide a more dangerous implementation: if the package is mainly a cinematography reference API and lacks claimed script writing, voice, anachronism, and Drive features, it is still a trust and integrity problem. Users may grant installation or permissions expecting one behavior while receiving another, which undermines informed consent and safe review.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The implemented skill is a general-purpose local file manager, which materially diverges from the declared cinematic script-writing purpose. This mismatch is dangerous because it can conceal broad filesystem read/write/delete capabilities behind an innocuous manifest, increasing the chance that users or reviewers grant the skill access they would not approve if its true behavior were disclosed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The implementation is a persistent todo-list manager, while the declared skill is a cinematic script writer. This capability mismatch is dangerous because it can mislead reviewers and users about what the skill actually does, potentially enabling unauthorized data storage and state manipulation under an unrelated trust boundary. In the context of an agent skill ecosystem, deceptive or mislabeled functionality materially increases supply-chain and user-consent risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file’s behavior is materially inconsistent with the declared cinematic-script-writer skill: it implements a weather client, performs external API calls, and stores weather data. In a skill ecosystem, capability/manifest mismatch is dangerous because it defeats user and reviewer expectations and can conceal unauthorized data access or network activity under an unrelated label.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: brace-expansion==1.1.12 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
95% confidence
Finding

brace-expansion 1.1.12 has multiple denial-of-service issues involving pathological brace patterns that can trigger extreme CPU or memory consumption. Although this instance is only transitively present in dev tooling, it remains a true vulnerability because tools handling attacker-controlled glob-like input could be stalled or crashed.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: minimatch==3.1.2 — 3 advisory(ies): CVE-2026-27904 (minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regu); CVE-2026-26996 (minimatch has a ReDoS via repeated wildcards with non-matching literal in patter); CVE-2026-27903 (minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adja)

High
Category
Supply Chain
Confidence
94% confidence
Finding

minimatch 3.1.2 is associated with ReDoS conditions from crafted glob patterns that cause catastrophic backtracking or combinatorial matching behavior. In this skill, the package is part of lint/test/build dependencies rather than production logic, which lowers exposure but does not eliminate the underlying denial-of-service risk in CI or local tooling.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: js-yaml==3.14.2 — 4 advisory(ies): CVE-2026-84375 (js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources); CVE-2026-59869 (js-yaml: YAML merge-key chains can force quadratic CPU consumption); GHSA-5p4m-2wfm-xmqj (JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026) +1 more

High
Category
Supply Chain
Confidence
90% confidence
Finding

js-yaml 3.14.2 has known CPU exhaustion issues when parsing specially crafted YAML merge structures. Here it is a transitive dev dependency, so the primary risk is denial of service in development or CI pipelines that parse untrusted YAML rather than compromise of end users at runtime.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: brace-expansion==2.0.2 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
95% confidence
Finding

brace-expansion 2.0.2 has the same class of DoS weaknesses as 1.x, allowing crafted expansion expressions to consume excessive CPU or memory. Even as a dev-only transitive dependency, it can still disrupt CI or local execution if exposed to attacker-controlled patterns.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: browserslist==4.28.1 — 2 advisory(ies): CVE-2026-73088 (Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.); CVE-2026-73089 (Browserslist: Unbounded memory growth (no cache eviction) via distinct query res)

High
Category
Supply Chain
Confidence
88% confidence
Finding

browserslist 4.28.1 is flagged for crash/prototype-write and unbounded memory growth issues under untrusted input conditions. In this repository it is part of development tooling, so impact is mainly denial of service or tooling instability, but prototype mutation risks can make CI/build contexts more fragile if they process attacker-supplied configuration.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: flatted==3.3.3 — 2 advisory(ies): CVE-2026-32141 (flatted vulnerable to unbounded recursion DoS in parse() revive phase); CVE-2026-33228 (Prototype Pollution via parse() in NodeJS flatted)

High
Category
Supply Chain
Confidence
91% confidence
Finding

flatted 3.3.3 is reported vulnerable to unbounded recursion DoS and prototype pollution during parse(). This is a real issue in the package, though here it is transitively present in development tooling, making the most likely impact build/test disruption or unsafe object mutation if untrusted serialized data is parsed.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: js-yaml==4.1.1 — 4 advisory(ies): CVE-2026-84375 (js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources); CVE-2026-59869 (js-yaml: YAML merge-key chains can force quadratic CPU consumption); GHSA-5p4m-2wfm-xmqj (JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026) +1 more

High
Category
Supply Chain
Confidence
90% confidence
Finding

js-yaml 4.1.1 retains reported CPU exhaustion issues on crafted YAML structures, making it vulnerable to denial of service when parsing attacker-controlled YAML. In the context of this skill repository, it appears in development tooling, so the risk is more to maintainers and CI systems than to end users of cinematic script generation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implemented skill is a generic template with greeting, memory, and calculation functions, but the manifest describes a cinematic script writing tool with Google Drive/script-generation capabilities. This mismatch is dangerous because users and orchestrators may grant trust, permissions, or invoke the skill under false assumptions, increasing the chance of unsafe tool exposure and policy bypass through unintended functionality.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The manifest claims this is a generic template skill rather than the advertised cinematic-script-writer skill, creating a strong identity mismatch between the package metadata and the expected behavior. This can mislead reviewers, users, and automated policy systems, and is especially dangerous because the same manifest also requests sensitive permissions that do not align with the declared template purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The declared tools, such as 'greet' and 'calculate', do not match the cinematic script-writing, character consistency, or cinematography functions described in the skill metadata provided for this review. A mismatch between advertised purpose and exposed tools is a security concern because it obscures actual functionality and can hide unintended or unauthorized behaviors behind an apparently harmless skill.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · skills/cinematic-script-writer/README.md (reported line 173)May include surrounding context.

md
- `createContext()` - Create story world
- `listContexts()` - List all contexts
- `getContext()` - Get specific context
- `deleteContext()` - Delete context

### Story Generation
- `generateStoryIdeas()` - Generate story ideas

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · skills/cinematic-script-writer/SKILL.md (reported line 142)May include surrounding context.

md
- `createContext()` - Create story world
- `listContexts()` - List all contexts
- `getContext()` - Get specific context
- `deleteContext()` - Delete context

### Story Generation
- `generateStoryIdeas()` - Generate story ideas

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · skills/cinematic-script-writer/index.ts (reported line 1435)May include surrounding context.

ts
era: string,
  style: string
) {
  return promptBuilder.createCharacterReference(
    characterId,
    characterName,
    visualDescription,

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · skills/cinematic-script-writer/index.ts (reported line 1470)May include surrounding context.

ts
era: string,
  style: string
) {
  return promptBuilder.createCharacterReference(
    characterId,
    characterName,
    visualDescription,

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · skills/cinematic-script-writer/index.ts (reported line 1489)May include surrounding context.

ts
era: string,
  style: string
) {
  return promptBuilder.createCharacterReference(
    characterId,
    characterName,
    visualDescription,

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
skills/cinematic-script-writer/storage-adapter.ts:70

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
skills/cinematic-script-writer/storage-manager.ts:184