Back to skill

Security audit

BoTTube — AI Video Platform SDK

Security checks for vulnerabilities and agentic risk

Overview

The basic BoTTube API skill is coherent, but the published artifact also contains hard-coded posting credentials and weak default admin keys for sensitive financial/admin workflows.

Review before installing or running. Do not run the bundled automation, bridge, or posting scripts against real services unless all embedded credentials are removed/rotated, admin keys are set to strong deployment-specific values, dependencies are pinned, and public posting or financial actions are explicitly authorized.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
post_giveaway_tweet.py:31
Finding

Hard-Coded X/Twitter OAuth Credentials in Executable Posting Script

Content
View full analysis
tweepy.Client: """Create and return a Tweepy client.""" return tweepy.Client( consumer_key="apwa7XeSfXPcYXcP0lTyweaqe", consumer_secret="syAIe9PpVJL2aQFSiZZDtBcXgxZ1uHijtgKqF0wFzOZF6B6n6W", access_token="1944928465121124352-P9hVuOuZoR790uYL7IjG6nJvoWCLBO", access_token_secret="lAn1I9xwyvhJJJRvRtMnDXtWuMUzNcTdjWiRIzpPlQ9aH", ) def post_tweet(client: tweepy.Client, text: str) -> Optional[str]: """Post a tweet and return the tweet ID. Returns: Tweet ID if successful, None otherwise """ try: response = client.create_tweet(text=text) return response.data.get('id') ``` ### Technical Analysis The executable script contains a complete OAuth credential set: consumer key, consumer secret, access token, and access-token secret. These are not placeholders; they are directly passed to `tweepy.Client`, and the resulting authenticated client calls `create_tweet`. Embedding credentials in source code makes them available to anyone who can read the repository, source archive, build artifact, or retained Git history. Removing them only from the current file would not be sufficient if they were previously committed to version control. The actual permissions available to an attacker depend on the scopes assigned to the access token. The code establishes that the token has at least been intended for posting content. ### Attack Path 1. An attacker obtains a copy of the public or otherwise exposed repository. 2. The attacker extracts the four OAuth values from `post_giveaway_tweet.py`. 3. The attacker initializes an X/Twitter API client using the exposed credentials. 4. If the credentials remain active, the attacker invokes API operations permitted by their scopes. ...[truncated 696 chars]
Remediation
View remediation
tweepy.Client: required = { "consumer_key": os.environ.get("TWITTER_CONSUMER_KEY"), "consumer_secret": os.environ.get("TWITTER_CONSUMER_SECRET"), "access_token": os.environ.get("TWITTER_ACCESS_TOKEN"), "access_token_secret": os.environ.get("TWITTER_ACCESS_TOKEN_SECRET"), } if not all(required.values()): raise RuntimeError("Required Twitter credentials are not configured") return tweepy.Client(**required) ``` ]]>

T05 · Unauthorized Access and Privilege Escalation

Error
Location
base_wrtc_bridge_blueprint.py:513
Finding

Public Default Administrator Key Authorizes Cryptocurrency Bridge Processing

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
package.json:2
Finding

Mutable and Unpinned Third-Party Package Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (703)

Tainted flow: 'BASE_RPC' from os.environ.get (line 28, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · base_wrtc_bridge_blueprint.py (reported line 147)May include surrounding context.

python
"params": [tx_hash],
            "id": 1,
        }
        resp = http_requests.post(BASE_RPC, json=payload, timeout=15)
        if not resp.ok:
            return None, f"RPC request failed: HTTP {resp.status_code}"

Tainted flow: 'BASE_RPC' from os.environ.get (line 28, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · base_wrtc_bridge_blueprint.py (reported line 167)May include surrounding context.

python
"params": [],
            "id": 2,
        }
        head_resp = http_requests.post(BASE_RPC, json=head_payload, timeout=10)
        if head_resp.ok:
            head_block = int(head_resp.json().get("result", "0x0"), 16)
            confirmations = head_block - tx_block

Tainted flow: 'OPENAI_MODEL' from os.environ.get (line 45, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · bottube_autonomous_agent.py (reported line 729)May include surrounding context.

python
# --- Tier 3: OpenAI API (if key is set) ---
    if OPENAI_API_KEY:
        try:
            r = requests.post(
                "https://api.openai.com/v1/chat/completions",
                headers={
                    "Authorization": f"Bearer {OPENAI_API_KEY}",

Tainted flow: 'COMFYUI_URL' from os.environ.get (line 33, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · bottube_autonomous_agent.py (reported line 1114)May include surrounding context.

python
}

    try:
        r = requests.post(f"{COMFYUI_URL}/prompt", json={"prompt": workflow}, timeout=30)
        if r.status_code != 200:
            log.error("ComfyUI queue failed: %d %s", r.status_code, r.text[:200])
            return None

Tainted flow: 'COMFYUI_URL' from os.environ.get (line 33, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · bottube_autonomous_agent.py (reported line 1124)May include surrounding context.

python
# Poll for completion (max 10 min)
        for _ in range(120):
            time.sleep(5)
            hr = requests.get(f"{COMFYUI_URL}/history/{prompt_id}", timeout=15)
            if hr.status_code == 200:
                hist = hr.json()
                if prompt_id in hist:

Tainted flow: 'dl_url' from os.environ.get (line 1135, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · bottube_autonomous_agent.py (reported line 1136)May include surrounding context.

python
subfolder = vid.get("subfolder", "")
                            # Download the video
                            dl_url = f"{COMFYUI_URL}/view?filename={fname}&subfolder={subfolder}&type=output"
                            dl = requests.get(dl_url, timeout=60)
                            if dl.status_code == 200:
                                tmp = f"/tmp/bottube_{bot_name}_{int(time.time())}.mp4"
                                with open(tmp, "wb") as f:

Tainted flow: 'url' from os.environ.get (line 226, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The request target is derived from the BOTTUBE_URL environment variable and used directly in authenticated POST requests, while the same requests include bot API keys in headers. In this script’s context, that means a modified environment can redirect traffic and credentials to an attacker-controlled endpoint, making the tainted flow materially dangerous rather than merely configurable behavior.

Content

Scanner excerpt · bottube_engage.py (reported line 229)May include surrounding context.

python
url = f"{BASE_URL}{endpoint}"
    headers = {"X-API-Key": api_key, "Content-Type": "application/json"}
    try:
        r = requests.post(url, json=data, headers=headers, verify=VERIFY_SSL, timeout=15)
        return r.status_code, r.json() if r.headers.get("content-type", "").startswith("application/json") else r.text
    except Exception as e:
        return 0, str(e)

Harmful Content Injection

Critical
Category
Prompt Injection
Confidence
95% confidence
Finding

This content may contain harmful instructions that could cause physical harm if followed. CRITICAL: Review carefully before use.

Content

Scanner excerpt · bottube_server.py (reported line 292)May include surrounding context.

python
# CSAM / child exploitation
    "csam", "child porn", "child sex", "cp links", "underage",
    "pedo", "paedo", "lolicon", "shotacon", "preteen",
    "jailbait", "kiddie", "minor sex", "child abuse",
    # Terrorism / extremism
    "how to make a bomb", "isis recruitment", "join isis",
    "jihad tutorial", "terrorist attack plan",
    # Gore / snuff
    "real murder", "snuff film", "execution video", "beheading",
    "real death video", "gore compilation",
    # Doxxing

Harmful Content Injection

Critical
Category
Prompt Injection
Confidence
95% confidence
Finding

This content may contain harmful instructions that could cause physical harm if followed. CRITICAL: Review carefully before use.

Content

Scanner excerpt · bottube_server.py (reported line 301)May include surrounding context.

python
"real death video", "gore compilation",
    # Doxxing
    "doxx", "leaked address", "leaked ssn", "leaked phone number",
    # Dangerous instructions
    "how to make meth", "how to make fentanyl", "synth fentanyl",
    "how to poison", "ricin recipe",
]

# Compiled patterns (word boundary matching where practical)
import re as _re_mod
_BLOCKLIST_PATTERN = _re_mod.compile(

Tainted flow: 'req' from os.getenv (line 3133, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · bottube_server.py (reported line 2600)May include surrounding context.

python
method="POST",
    )
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            raw = resp.read().decode("utf-8", errors="replace")
            return resp.getcode(), json.loads(raw) if raw else {}
    except urllib.error.HTTPError as e:

Tainted flow: 'req' from os.getenv (line 3133, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · bottube_server.py (reported line 3139)May include surrounding context.

python
headers={"Content-Type": "application/json"},
                method="POST",
            )
            urllib.request.urlopen(req, timeout=10)
        except Exception:
            pass  # Fire-and-forget; never block on failure
    threading.Thread(target=_do_ping, daemon=True).start()

Tainted flow: 'req' from os.environ.get (line 3995, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · bottube_server.py (reported line 4007)May include surrounding context.

python
method="POST",
                )
                try:
                    with urllib.request.urlopen(req, timeout=10) as resp:
                        if 200 <= getattr(resp, "status", 200) < 300:
                            ok = True
                            break

Tainted flow: 'req' from os.environ.get (line 3995, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · bottube_server.py (reported line 13600)May include surrounding context.

python
method="POST",
                )
                try:
                    with urllib.request.urlopen(req, timeout=10) as resp:
                        if 200 <= getattr(resp, "status", 200) < 300:
                            ok = True
                            break

Tainted flow: 'req' from os.environ.get (line 3995, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · bottube_server.py (reported line 13671)May include surrounding context.

python
method="POST",
                )
                try:
                    with urllib.request.urlopen(req, timeout=10) as resp:
                        if 200 <= getattr(resp, "status", 200) < 300:
                            ok = True
                            break

Tainted flow: 'req' from os.environ.get (line 3995, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · bottube_server.py (reported line 13798)May include surrounding context.

python
method="POST",
                )
                try:
                    with urllib.request.urlopen(req, timeout=10) as resp:
                        if 200 <= getattr(resp, "status", 200) < 300:
                            ok = True
                            break

Tainted flow: 'req' from os.environ.get (line 3995, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · bottube_server.py (reported line 13821)May include surrounding context.

python
method="POST",
                )
                try:
                    with urllib.request.urlopen(req, timeout=10) as resp:
                        if 200 <= getattr(resp, "status", 200) < 300:
                            ok = True
                            break

Tainted flow: 'req' from os.environ.get (line 3995, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · bottube_server.py (reported line 13867)May include surrounding context.

python
method="POST",
                )
                try:
                    with urllib.request.urlopen(req, timeout=10) as resp:
                        if 200 <= getattr(resp, "status", 200) < 300:
                            ok = True
                            break

Tainted flow: 'req' from os.environ.get (line 3995, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · bottube_server.py (reported line 13921)May include surrounding context.

python
method="POST",
                )
                try:
                    with urllib.request.urlopen(req, timeout=10) as resp:
                        if 200 <= getattr(resp, "status", 200) < 300:
                            ok = True
                            break

Tainted flow: 'token_req' from os.environ.get (line 5983, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · bottube_server.py (reported line 5988)May include surrounding context.

python
data=token_data,
            headers={"Content-Type": "application/x-www-form-urlencoded"},
        )
        with urllib.request.urlopen(token_req, timeout=10) as resp:
            tokens = json.loads(resp.read())
    except Exception:
        flash("Failed to exchange Google authorization code.", "error")

Tainted flow: 'req' from os.getenv (line 3133, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · bottube_server.py (reported line 9441)May include surrounding context.

python
method="POST",
    )
    try:
        resp = urllib.request.urlopen(req, timeout=10)
        return jsonify({"ok": True, "status": resp.status})
    except Exception as e:
        return jsonify({"ok": False, "error": str(e)}), 502

Tainted flow: 'WHISPER_MODEL' from os.environ.get (line 39, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · captions_blueprint.py (reported line 368)May include surrounding context.

python
try:
        with open(audio_path, "rb") as handle:
            response = requests.post(
                WHISPER_API_URL,
                headers={"Authorization": f"Bearer {OPENAI_API_KEY}"},
                data={"model": WHISPER_MODEL, "response_format": "verbose_json"},

Tainted flow: 'url' from os.environ.get (line 465, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · cosmo_nasa_bot.py (reported line 62)May include surrounding context.

python
def fetch_apod():
    """Fetch today's Astronomy Picture of the Day."""
    url = f"https://api.nasa.gov/planetary/apod?api_key={NASA_API_KEY}"
    r = requests.get(url, timeout=30)
    r.raise_for_status()
    data = r.json()

Tainted flow: 'url' from os.environ.get (line 465, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · cosmo_nasa_bot.py (reported line 86)May include surrounding context.

python
def fetch_apod():
    """Fetch today's Astronomy Picture of the Day."""
    url = f"https://api.nasa.gov/planetary/apod?api_key={NASA_API_KEY}"
    r = requests.get(url, timeout=30)
    r.raise_for_status()
    data = r.json()

Tainted flow: 'url' from os.environ.get (line 465, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · cosmo_nasa_bot.py (reported line 128)May include surrounding context.

python
def fetch_apod():
    """Fetch today's Astronomy Picture of the Day."""
    url = f"https://api.nasa.gov/planetary/apod?api_key={NASA_API_KEY}"
    r = requests.get(url, timeout=30)
    r.raise_for_status()
    data = r.json()

Tainted flow: 'url' from os.environ.get (line 465, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · cosmo_nasa_bot.py (reported line 184)May include surrounding context.

python
def fetch_apod():
    """Fetch today's Astronomy Picture of the Day."""
    url = f"https://api.nasa.gov/planetary/apod?api_key={NASA_API_KEY}"
    r = requests.get(url, timeout=30)
    r.raise_for_status()
    data = r.json()

Static analysis

Detected: suspicious.dynamic_code_execution, suspicious.exposed_resource_identifier, suspicious.exposed_secret_literal (+2 more)

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
bottube_static/swaggerui/swagger-ui-bundle.js:3

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
bottube_static/swaggerui/swagger-ui-standalone-preset.js:3

Plaintext HTTP endpoint targets a CGNAT/Tailscale-range address.

Critical
Code
suspicious.exposed_resource_identifier
Location
generation/providers/comfyui_ltx.py:28

Plaintext HTTP endpoint targets a CGNAT/Tailscale-range address.

Critical
Code
suspicious.exposed_resource_identifier
Location
video_gen_blueprint.py:43

Plaintext HTTP endpoint targets a CGNAT/Tailscale-range address.

Critical
Code
suspicious.exposed_resource_identifier
Location
vision_screener.py:30

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
bottube_server.py:4109

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
bottube_static/swaggerui/swagger-ui-bundle.js:3

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
bottube_templates/blog_build_bot.html:319

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
bottube_templates/upload.html:442

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
bottube_x402.py:166

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
cosmo_nasa_bot.py:759

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
ergo_bridge_blueprint.py:273

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
gemini_blueprint.py:303

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
generation/routes.py:49

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
google_indexing.py:74

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
mobile-app/__tests__/types.test.ts:99

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
mobile-app/src/hooks/useAuth.ts:88

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
post_giveaway_tweet.py:34

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
sdk/tests/sdk.test.js:10

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
search_blueprint.py:352

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
syndication_routes.py:73

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
tests/test_badges.py:157

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
tests/test_founding_leaderboard.py:157

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
tests/test_referrals.py:208

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
tests/test_upload_api.py:158

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
usdc_blueprint.py:183

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
video_gen_blueprint.py:130

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
wrtc_bridge.py:122

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
social_orchestrate.py:52

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
telegram_bot.py:106

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
scraper_detective.py:166

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
tests/test_upload_api.py:66