Back to skill

Security audit

Video Sourcing

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-aligned for video sourcing, but it automatically downloads and runs external code on the host with API keys, which needs careful review before installation.

Install only if you trust the upstream Memories-ai-labs runtime and are comfortable with host execution. Use low-privilege, quota-limited Google and YouTube keys, avoid sensitive query text, and prefer reviewing or pinning the runtime to an immutable commit before use.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/run_video_query.sh:61
Finding

Unverified Remote Runtime Retrieval and Execution with API Credentials

Content
View full analysis
/dev/null 2>&1 || { log_error "Failed to clone ${PINNED_REPO_URL} at tag ${PINNED_TAG}." log_error "Check network access and that the release tag exists." exit 2 } else ( cd "${MANAGED_RELEASE_DIR}" git fetch --depth 1 origin "refs/tags/${PINNED_TAG}:refs/tags/${PINNED_TAG}" >/dev/null 2>&1 || true git checkout --detach "${PINNED_TAG}" >/dev/null 2>&1 || { log_error "Failed to checkout pinned runtime tag ${PINNED_TAG}." exit 2 } ) fi ( cd "${MANAGED_RELEASE_DIR}" uv sync --frozen --no-dev >/dev/null 2>&1 || { log_error "Failed to install runtime dependencies with uv sync." exit 2 } ) } ``` ```bash main() { require_binary uv require_env_key GOOGLE_API_KEY require_env_key YOUTUBE_API_KEY RUNTIME_ROOT="$(resolve_runtime_root)" cd "${RUNTIME_ROOT}" uv run python -m video_sourcing_agent.integrations.openclaw_runner "$@" } ``` The associated Skill instruction explicitly requires unsandboxed execution: ```markdown This workflow expects host runtime execution (sandbox mode off). The runner auto-bootstraps a pinned runtime from `Memori ...[truncated 3729 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill is designed to source videos from external platforms and requires API keys for Google and YouTube, which strongly implies that user queries may be transmitted to third-party services. Without a clear disclosure in the skill description, users may unknowingly send sensitive prompts, brand research, or investigative queries to external platforms and API providers, creating privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly requires host runtime execution and states it will auto-bootstrap external code from a GitHub-hosted project when a local path is not set, but the user-facing description does not warn about either behavior. This is dangerous because users may invoke the skill without understanding that untrusted or changing third-party code will run on the host outside the sandbox, increasing supply-chain and local system risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script is presented as a deterministic wrapper, but it dynamically clones a remote GitHub repository and installs dependencies at runtime. Even with a pinned tag, this expands the trust boundary to remote source code, package resolution, and network availability, making the skill non-deterministic in practice and exposing users to supply-chain compromise or unexpected code execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The bootstrap logic deletes the managed release directory with rm -rf when it detects a directory that is not a git checkout. Although the path is partially controlled by internal variables, it still performs destructive deletion automatically and without confirmation, creating risk of unintended data loss if the base path is misconfigured or manipulated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

After downloading the repository, the script runs uv sync and then executes python -m from that runtime, which means unreviewed downloaded code and its dependencies are installed and executed automatically. In an agent skill, this is especially risky because the advertised functionality understates that arbitrary remote project code will run with the user's environment and API keys available.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script requires GOOGLE_API_KEY and YOUTUBE_API_KEY but the manifest description does not disclose use of external credentials. This can cause operators to grant sensitive API access without clear understanding of data flow, billing exposure, or third-party service interaction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script silently clones and updates a remote repository over the network during normal execution. In this skill context, undisclosed network retrieval is dangerous because it changes runtime behavior based on external state and introduces a supply-chain attack surface that users may not expect from a chat wrapper.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.