Back to skill

Security audit

ja-script-subtitle

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Japanese-audio subtitle workflow; its network setup and WorkBuddy download helper are purpose-aligned but should be used only with user-provided files or node IDs.

Install this only if you are comfortable with it creating /opt/wenv, installing Python packages, downloading a Whisper model, using ffmpeg, and optionally fetching WorkBuddy library files by node ID. Provide only node IDs and files you are authorized to access.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a subtitle-generation workflow, but it also contains instructions to fetch files from an internal library service using node IDs and short-lived presigned URLs. That hidden retrieval behavior expands the trust boundary beyond local subtitle processing and can enable unauthorized or unexpected access to remote resources, especially if an agent follows the instructions automatically.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill explicitly instructs use of shell commands, network access, environment-variable changes, and file-writing, but it declares no tool scope or permission boundaries. That creates an authorization gap where an agent may execute higher-risk capabilities than a reviewer or platform expects, increasing the chance of unintended file access, command execution, or external data transfer.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This file contains natural-language instructions and status messages exclusively in Chinese, including the main docstring and printed output. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale constraint is explicitly justified, which it is not here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes a Japanese subtitle workflow that consumes scripts and audio to produce SRTs or burned-in videos. This file instead implements a general-purpose WorkBuddy library file fetcher, taking arbitrary node IDs and filenames and downloading the referenced content, which is not specific to subtitle generation or Japanese media processing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Natural-language policy checks apply to all file types, including code docstrings. The user-facing instructions, background, and examples are exclusively in Chinese, and the file does not indicate that the language choice is optional or required for a region-specific purpose.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/fetch_library_file.py (reported line 30)May include surrounding context.

python
def get_url(node_id):
    r = subprocess.run([sys.executable, GEN, "--node-id", node_id],
                       capture_output=True, text=True)
    for line in r.stdout.splitlines():
        if line.startswith("KS_DRIVE_DOWNLOAD"):

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest focuses on transforming provided Japanese scripts and audio into subtitles and optional videos; it does not mention remote retrieval from WorkBuddy or network access. This script resolves a download link via another tool and then fetches file contents over HTTP, adding a remote data access capability beyond the described processing role.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script performs package installation and remote model retrieval automatically, without prompting the operator or clearly warning that it will modify the environment and contact third-party endpoints. In security-sensitive or offline-controlled environments, this can lead to unreviewed code/artifact ingestion, unexpected egress, and supply-chain exposure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a Japanese subtitle generation pipeline, but this script performs environment bootstrapping that installs dependencies from PyPI and fetches Whisper model artifacts via a Hugging Face mirror. Network-based package/model provisioning is not part of the user-facing subtitle function itself and introduces a broader capability than the stated skill purpose implies.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The transcribe call forces language="ja", which is a natural-language locale constraint. The file does not present this as an explicit user opt-in or clearly document that the skill is intentionally limited to a Japan-specific compliance or locale-bound use case.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This is a code file, so missing-warning checks apply. The script performs an HTTP download and saves the response to a local file, but there is no confirmation prompt, cautionary comment near the operation, or other user-facing disclosure about the network transfer and overwrite/write behavior beyond the basic usage docstring.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The header comments frame the script as a constrained-sandbox preparation path, yet the actual commands create a venv, install packages, and download model assets from external services. This is not merely incomplete documentation: the comments emphasize environmental constraints while the code relies on privileged installation and outbound network behavior to bypass them.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language comments and status output are written in Chinese only, which imposes a specific language without offering user opt-in or documenting a justified locale constraint. This can violate language/locale policy when the skill is not clearly scoped to a Chinese-only audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.