Back to skill

Security audit

Video Frame Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-aligned for video frame analysis, but its documented command can accidentally execute a spoofed script from another installed skill directory.

Review before installing. Only run it on videos you intend to analyze, choose a non-sensitive output directory, and prefer fixing the documented command to call this skill's packaged references/smart_extract.py by exact path. Install dependencies in an isolated environment with pinned versions when possible.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T07 · Tool Hijacking and Spoofing

Warning
Location
SKILL.md:52
Finding

Ambiguous Script Discovery Can Execute a Spoofed Skill Tool

Content
View full analysis
/dev/null | head -1)")" python "$SKILL_DIR/smart_extract.py" "你的视频路径.mp4" "视频名_frames/" 15 ``` ### Technical Analysis The documented workflow recursively searches the entire shared `~/.workbuddy/skills` directory for any file named `smart_extract.py` and executes the first result. The selected file is not verified as belonging to this Skill, and the discovery order produced by `find` is not a security boundary. The audited script is packaged at `references/smart_extract.py`, but the command does not resolve that known package-relative path. Consequently, another installed Skill or a local process with write access to the shared skills directory could place a different file with the same name in a directory returned earlier by `find`. Because the selected file is passed directly to the Python interpreter, a spoofed script would execute arbitrary Python code with the permissions of the user or agent running the workflow. ### Attack Path 1. An attacker obtains the ability to install another Skill or write a file under `~/.workbuddy/skills`. 2. The attacker creates a malicious file named `smart_extract.py` in a location likely to be returned before the legitimate script. 3. A user invokes the documented video-analysis workflow. 4. The `find` command discovers both legitimate and attacker-controlled files. 5. `head -1` selects the first result without checking its package ownership or canonical path. 6. Python executes the attacker-controlled script under the agent's current account. ### Impact Assessment Successful exploitation permits arbitrary local code execution with the same privileges as the agent process. The malicious script could read or modify files accessible to that account, alter generat ...[truncated 288 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:143
Finding

Third-Party Dependencies Are Installed Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents the skill as an end-to-end AI video analysis system for short dramas, including key-frame extraction, detailed multimodal interpretation, and structured analytical reporting. The provided code chunk only implements a basic utility script for extracting frames from a video at fixed intervals and saving them as JPEG images. While frame extraction is related as a supporting preprocessing step, the actual code lacks all of the core advertised analysis capabilities and reporting functions. This is therefore a material description-behavior mismatch, with the code representing only a narrow fallback component rather than the declared primary purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The supplied code implements a narrow preprocessing utility: smart keyframe extraction based on scene-change detection plus time-based sampling. That partially matches the first step of the description ('自动提取关键帧'), but none of the larger advertised capabilities are present. There is no model invocation, no image understanding, no text extraction, no report synthesis, and no business-analysis logic. Therefore the declared description materially overstates the skill's actual behavior and primary purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README instructs users to upload a video or provide a video path, but it does not warn about the privacy and local file access implications of processing arbitrary media files. In practice, this can normalize passing sensitive local paths or private videos into the skill without informed consent, especially when combined with a broad invocation pattern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The invocation phrase "分析这个视频" is extremely generic and likely to match ordinary user requests unrelated to intentionally using this skill. In an agent ecosystem, broad triggering language can cause the skill to activate unexpectedly, leading to unintended processing of user-provided files or media and increasing the chance of accidental data exposure or unauthorized local file handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs the agent to create and append to multiple local files during analysis, but it does not clearly warn the user up front that local artifacts will be created and modified. In a workspace with sensitive data or strict change controls, silent file creation can surprise users, overwrite existing reports, or leave behind sensitive analysis outputs derived from private videos.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases are very broad, everyday requests such as '分析这个视频' and '帮我分析竞品视频', which can cause the skill to activate in situations the user did not intend. In an agent environment, unintended activation can lead to unexpected file reads/writes, tool invocation, or processing of sensitive local video content without sufficiently explicit user consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.