Back to skill

Security audit

jl-video-downloader

Security checks for vulnerabilities and agentic risk

Overview

This video downloader skill has a coherent purpose, but its bundled setup and wrapper scripts create avoidable command-execution, supply-chain, sensitive-data, and shell-persistence risks.

Install only after the publisher removes eval from download.sh, pins and verifies external packages, replaces curl-pipe-to-shell setup, makes shell startup changes opt-in, and adds clear privacy guidance for API keys, cookies, media, and transcript data.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/setup.sh:34
Finding

Unverified Remote Installer Is Downloaded and Executed Through a Shell

Content
View full analysis
/dev/null; then log_warning "未找到uv工具,正在安装..." curl -LsSf https://astral.sh/uv/install.sh | sh if [[ $? -eq 0 ]]; then log_success "uv安装成功" # 添加uv到PATH export PATH="$HOME/.cargo/bin:$PATH" else log_error "uv安装失败" return 1 fi fi ``` The same unsafe installation instruction is presented to users in two documentation files: ```bash curl -LsSf https://astral.sh/uv/install.sh | sh ``` ### Technical Analysis The script retrieves a mutable response from an external URL and passes it directly to `sh`. There is no version pinning, cryptographic signature verification, checksum validation, local inspection, or separation between download and execution. HTTPS provides transport protection but does not establish that the retrieved script is immutable or safe. Compromise of the hosting infrastructure, publishing process, domain, or relevant trust chain could replace the installer after this Skill has already passed review. Installing `uv` is relevant to the declared functionality, but immediate execution of a mutable remote script is not the minimum-privilege or minimum-risk way to satisfy that dependency. A system package, pinned release artifact, or separately downloaded and verified installer would avoid this execution pattern. ### Attack Path 1. A user or Agent invokes `./scripts/setup.sh install`. 2. The script determines that `uv` is not currently available. 3. The script requests the current contents of `https://astral.sh/uv/install.sh`. 4. The response is immediately interpreted by `sh`. 5. If the remote source or delivery path has been compromised, attacker-controlled commands execute with all privileges and fi ...[truncated 757 chars]
Remediation
View remediation
/install.sh" printf '%s %s\n' "" "/tmp/uv-installer.sh" | sha256sum --check - sh /tmp/uv-installer.sh rm -f /tmp/uv-installer.sh ``` The actual release URL and digest must come from authenticated, publisher-supported release metadata. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/download.sh:290
Finding

Shell Command Injection Through Dynamically Constructed Command and eval

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/setup.sh:61
Finding

Unpinned Third-Party Downloader Is Automatically Installed, Upgraded, and Executed

Content
View full analysis
/dev/null; then log_success "jl-video-downloader 命令测试成功" else log_error "jl-video-downloader 命令测试失败" return 1 fi ``` Normal operation also executes the package: ```bash local uvx_cmd="uvx jl-video-downloader" ... eval "$uvx_cmd" ``` ### Technical Analysis The project does not include the implementation of `jl-video-downloader`. Instead, it installs the latest version resolved by `uv`, automatically upgrades existing installations, and executes the resulting package. No exact version, lockfile, package hash, source revision, publisher signature, or reviewed dependency set is provided. The documentation additionally suggests several alternative package indexes. Each index adds another supply-chain trust boundary and may serve different package contents or dependency versions. Because the package performs the core downloading and transcription behavior, it is expected to receive URLs and inherit environment variables containing API keys, proxy settings, and potentially platform cookies. Consequently, a compromised package release or transitive dependency would execute in a sensitive context. This is distinct from the remote shell installer issue: even if `uv` is installed securely, the downlo ...[truncated 1208 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (60)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The transcription/extraction workflow requires API keys and implies uploading video or audio-derived content to external services, but the documentation does not provide a privacy or data-handling warning. In this context, that omission is significant because users may unknowingly send private media, transcripts, or metadata to third-party providers.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
77% confidence
Finding

Appending source ~/.jl-video-downloader/load_env.sh to ~/.bashrc creates persistent shell startup modification. While likely intended for convenience rather than malware persistence, this is still a meaningful persistence behavior because it causes future shells to automatically execute content from a user-writable path.

Content

Scanner excerpt · SKILL.md (reported line 275)May include surrounding context.

E="$HOME/.jl-video-downloader/video-dl.log"

text

**使用脚本自动配置:**
```bash
# 复制示例配置文件
cp ~/.openclaw/workspace/skills/jl-video-downloader/scripts/env.example ~/.jl-video-downloader/env

# 编辑配置文件
nano ~/.jl-video-downloader/env

# 加载配置
source ~/.jl-video-downloader/load_env.sh

添加到shell配置

bash
# 添加到 ~/.bashrc 或 ~/.zshrc
echo 'source ~/.jl-video-downloader/load_env.sh' >> ~/.bashrc

# 或使用脚本自动添加
cd ~/.openclaw/workspace/skills/jl-video-downloader/scripts
./setup.sh config

故障排除

常见问题

1. "uv: command not found"

bash
# 安装uv工具
curl -LsSf https://astral.sh/uv/install.sh | sh
# 或
pip install uv

2. "ffmpeg: command not found"

bash
# Ubuntu/Debian
sudo apt-get install ffmpeg

# macOS
brew install ffmpeg

# CentOS/RHEL
sudo yum install ffmpeg

3. API密钥错误

bash
# 检查环境变量
echo $SILI_FLOW_API_KEY
echo $DEEPSEEK_API_K

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

Piping curl output to sh is a chaining pattern that turns a network fetch directly into code execution. This removes opportunities for inspection and makes compromise of the remote host or transport immediately exploitable.

Content

Scanner excerpt · SKILL.md (reported line 289)May include surrounding context.

1. "uv: command not found"

bash
# 安装uv工具
curl -LsSf https://astral.sh/uv/install.sh | sh
# 或
pip install uv

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Although the target path is scoped to a cache directory, the documentation recommends a forceful recursive delete with a shell glob. In user-run shell contexts, destructive commands become dangerous if environment variables or paths are altered unexpectedly, and skills should avoid normalizing unsafe deletion patterns.

Content

Scanner excerpt · SKILL.md (reported line 465)May include surrounding context.

export VIDEO_DOWNLOADER_CACHE_DIR="$HOME/.cache/jl-video-downloader"

清理缓存

rm -rf ~/.cache/jl-video-downloader/*

text

## 更新和维护

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Although the target path is scoped to a cache directory, the documentation recommends a forceful recursive delete with a shell glob. In user-run shell contexts, destructive commands become dangerous if environment variables or paths are altered unexpectedly, and skills should avoid normalizing unsafe deletion patterns.

Content

Scanner excerpt · SKILL.md (reported line 465)May include surrounding context.

export VIDEO_DOWNLOADER_CACHE_DIR="$HOME/.cache/jl-video-downloader"

清理缓存

rm -rf ~/.cache/jl-video-downloader/*

text

## 更新和维护

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The | sh pattern executes network-fetched content immediately, making the command vulnerable to server compromise, MITM in misconfigured environments, DNS hijack, or accidental script changes. This is more dangerous in this skill context because it appears in troubleshooting/setup instructions, where users are conditioned to run it quickly to resolve blockers.

Content

Scanner excerpt · scripts/README.md (reported line 160)May include surrounding context.

1. "uv: command not found"

bash
# 安装uv
curl -LsSf https://astral.sh/uv/install.sh | sh

2. "ffmpeg: command not found"

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

curl ... | sh executes remote code directly from the network without verification, review, or user confirmation. If the upstream server, transport, or install script is compromised, the user's machine will run attacker-controlled shell commands during installation.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Piping network data directly into sh creates a command-execution chain with no inspection boundary. This is a classic high-risk pattern because any attacker able to influence the fetched content gains immediate shell execution under the current user.

Content

Scanner excerpt · scripts/setup.sh (reported line 38)May include surrounding context.

sh
# 检查uv
    if ! command -v uv &> /dev/null; then
        log_warning "未找到uv工具,正在安装..."
        curl -LsSf https://astral.sh/uv/install.sh | sh
        if [[ $? -eq 0 ]]; then
            log_success "uv安装成功"
            # 添加uv到PATH

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description activates on broad download and extraction intents but does not warn that it writes files to disk, creates configuration under the user's home directory, and may modify shell startup behavior through setup guidance. Lack of up-front disclosure increases the risk of users invoking the skill without informed consent about filesystem changes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill repeatedly instructs users to execute uvx jl-video-downloader without pinning an exact package version or hash. Because uvx resolves and runs the latest available package from a remote registry, a compromised upstream release or typosquatted replacement could result in arbitrary code execution on the host.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This invocation runs an unpinned remote package via uvx, which creates a supply-chain execution path. If the package publisher account, dependency chain, or index is compromised, the agent may execute attacker-controlled code with the user's permissions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill's documentation normalizes unpinned execution of a remote package with uvx, exposing users to upstream package tampering. In a skill context, this is more dangerous because users may copy-paste commands verbatim and grant the downloaded code direct shell execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Running uvx jl-video-downloader without version pinning permits silent drift to newly published code. That makes the behavior nondeterministic and increases the risk of remote code execution through a malicious or hijacked package update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This unpinned uvx example allows arbitrary upstream package changes to alter what code is executed. Since the skill is intended for media processing and network access, compromise could expose downloaded content, credentials, or local files.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The command relies on implicit trust in the latest package state from a public registry. That is a real supply-chain risk because execution occurs immediately after resolution, giving malicious code direct access to the environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The example invokes a remote package dynamically without version locking, making the executed code mutable over time. In an automation skill, that increases the chance that future runs behave differently or maliciously without any skill file change.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Using uvx without version pinning is a genuine dependency-trust problem, not just a style issue. An attacker controlling the package or its dependencies could gain code execution when users follow the documented command.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This instruction executes an unpinned external tool from the package ecosystem. Because the skill also encourages use with proxies and API keys, compromise could additionally leak sensitive network settings or credentials.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The unpinned command introduces a real supply-chain attack surface by trusting whatever package version is current at run time. That is particularly risky in a shell-enabled skill because the executed package can read, write, and exfiltrate local data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This example continues the pattern of executing a mutable external package via uvx without version constraints. If upstream content changes maliciously, users following the docs could run unauthorized code on their systems.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The command trusts remote package resolution at execution time, which is a true security weakness. Attackers can exploit compromised publishing credentials or dependency confusion to replace the executed code path.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Because uvx runs an external package immediately, omitting version pinning allows silent upstream changes to become local execution. In practice, that can lead to remote code execution and credential or file theft.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This invocation exposes users to the same unpinned package execution risk. The context makes it more dangerous because the skill encourages repeated operational use, increasing the chance a future malicious release will be consumed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.