Back to skill

Security audit

ffmpeg剪辑大师

Security checks for vulnerabilities and agentic risk

Overview

The skill is a local FFmpeg editing toolkit, but it can overwrite user-chosen files without confirmation.

Install only if you are comfortable with a local media tool that runs FFmpeg and writes files on your machine. Use dedicated output folders, avoid reusing important filenames, and review any agent-proposed --output or --output-dir path before execution.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/common.py:208
Finding

Caller-Controlled Output Paths Are Silently Overwritten

Content
View full analysis
subprocess.CompletedProcess: _check_binaries() # Ensure -y is present for overwrite if "-y" not in cmd: idx = cmd.index("ffmpeg") + 1 cmd.insert(idx, "-y") _ensure_logging() log_params("FFmpeg 执行开始", cmd=" ".join(cmd)) start = time.monotonic() if capture_output: result = subprocess.run(cmd, capture_output=True, text=True) elapsed = round(time.monotonic() - start, 3) if result.returncode != 0: print(f"FFmpeg stderr:\n{result.stderr}", file=sys.stderr) log_params("FFmpeg 执行失败", elapsed=elapsed, returncode=result.returncode) raise subprocess.CalledProcessError(result.returncode, cmd) log_params("FFmpeg 执行完成", elapsed=elapsed) return result else: result = subprocess.run(cmd) elapsed = round(time.monotonic() - start, 3) if result.returncode != 0: log_params("FFmpeg 执行失败", elapsed=elapsed, returncode=result.returncode) raise subprocess.CalledProcessError(result.returncode, cmd) log_params("FFmpeg 执行完成", elapsed=elapsed) return result ``` Caller-controlled output paths are accepted without confinement or existence checks: ```python # scripts/video_subtitle.py:38,50 parser.add_argument("--output", type=Path, help="输出文件路径(不指定则自动生成)") output_path = args.output or build_output_path("subtitle", input_path, suffix=suffix) ``` ```python # scripts/video_watermark.py:48,55 parser.add_argument("--output", type=Path, help="输出文件路径") output_path = args.output or build_output_ ...[truncated 1704 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/video_concat.py:44
Finding

Unescaped Input Is Embedded into FFmpeg Manifests and Filter Graphs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (38)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares executable dependencies and explicitly instructs use of local Python and FFmpeg scripts, but does not define any tool scope such as permissions or allowed-tools. That increases the chance an agent will invoke shell or environment access more broadly than intended, which is risky in a file-processing skill that handles user-supplied paths and local files.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger description is very broad and includes semantic catch-alls such as similar-meaning terms, causing the skill to activate for many loosely related requests. Over-broad invocation can route unrelated user tasks into a shell-capable local-processing skill, increasing the chance of unintended command execution, file handling, or misuse of local resources.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

All user-facing natural-language instructions in the skill are written in Chinese, and the file does not indicate that the skill is Chinese-only by design or that users may choose another language. Under the language/locale policy, a skill should not implicitly force a language without opt-in or a documented regional justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The default_prompt trigger is broad enough to activate on many general requests about media editing or file processing, which can cause over-invocation of the skill beyond narrowly intended FFmpeg tasks. In an agent system, this increases the chance that local multimedia files are pulled into a workflow unnecessarily, creating scope creep, unintended file handling, or user confusion about what tool is operating on their data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The user-facing argparse description and option help strings are entirely in Chinese, which imposes a specific language on all users of the skill. There is no indication of language choice, fallback, or justification for a Chinese-only locale, so this is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script invokes FFmpeg with the -y flag, which forces overwriting of an existing output file without confirmation. In a local file-processing skill, this can cause unintended data loss if the computed or user-supplied output path points to an existing media file, especially since the tool is designed to manipulate local user content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The argument parser description and help text are presented only in Chinese, and the error message later in the file is also Chinese-only. This imposes a specific language on users without any opt-in or indication that the tool is intentionally limited to a Chinese-speaking context, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The argparse description and help text are entirely hard-coded in Chinese, which imposes a specific language on users without any visible opt-in or alternative locale support. This is a natural-language policy concern because the file embeds a fixed language choice rather than offering user selection or documenting a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This file contains natural-language strings presented to users/operators in Chinese, such as error messages, log event names, and output labels, with no mechanism for language selection. That can violate language/locale policy when the skill is expected to support users without forcing a specific language by default.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/common.py (reported line 182)May include surrounding context.

python
]
    _ensure_logging()
    log_params("FFprobe 执行", input=str(input_path))
    result = subprocess.run(cmd, capture_output=True, text=True, check=True)
    data = json.loads(result.stdout)

    fmt = data.get("format", {})

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The helper forcibly injects -y into every ffmpeg command, which causes silent overwrite of existing files. In a multimedia-editing skill that operates on local files and predictable output paths, this can destroy prior outputs or clobber user-selected files if path construction or caller behavior is mistaken, making accidental data loss materially more likely.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/common.py (reported line 224)May include surrounding context.

python
start = time.monotonic()
    if capture_output:
        result = subprocess.run(cmd, capture_output=True, text=True)
        elapsed = round(time.monotonic() - start, 3)
        if result.returncode != 0:
            print(f"FFmpeg stderr:\n{result.stderr}", file=sys.stderr)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/common.py (reported line 233)May include surrounding context.

python
log_params("FFmpeg 执行完成", elapsed=elapsed)
        return result
    else:
        result = subprocess.run(cmd)
        elapsed = round(time.monotonic() - start, 3)
        if result.returncode != 0:
            log_params("FFmpeg 执行失败", elapsed=elapsed, returncode=result.returncode)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code performs a file-writing operation and explicitly forces overwrite behavior by passing '-y' to ffmpeg. The file itself contains no confirmation prompt, warning message, or explanatory comment/docstring disclosing that an existing output file may be replaced automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The ffmpeg command is invoked with -y, which forces overwriting an existing output file without any confirmation. In a multimedia-editing skill that operates on local user files, this can cause silent data loss if the output path collides with an existing file or if output naming is guessed incorrectly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The argument parser description and option help strings are written only in Chinese, and the script later emits a Chinese-only error message. This imposes a specific language on users without opt-in or documented justification, which matches the locale/language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script creates an output directory and writes image files, and the ffmpeg commands include '-y', which forces overwrite of existing files without prompting. While comments describe frame extraction, there is no visible user-facing warning, confirmation, or print/log message disclosing that existing outputs may be overwritten.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The user-facing argument descriptions are all presented in Chinese, which forces a specific language for interacting with the skill. This is a natural-language policy concern because the file provides no opt-in, fallback, or documentation indicating that the skill is intentionally limited to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code creates an output directory and invokes ffmpeg with the '-y' flag, which forces overwriting output files if matching segment names already exist. There is no confirmation prompt or user-facing warning in the script about file creation or overwrite behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The user-facing argparse description and help strings are entirely in Chinese, which imposes a specific language on all users of the skill. There is no opt-in, alternative locale, or indication that this skill is intentionally limited to a Chinese-speaking environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The argument parser description and help text force a specific language for all users. Under the stated policy, locale-specific language is a violation unless the skill offers opt-in or clearly documents and justifies the constraint, which this file does not do.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The argparse description and help text are all hard-coded in Chinese, which imposes a specific language on users without opt-in or an alternative locale path. This matches the policy category for language or locale constraints that are not optional or explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The user-facing name and description are in Chinese, but the activation instruction in the default prompt is entirely in English. This creates a language inconsistency that can impose a locale expectation without explicit user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The argument parser description and help strings are written only in Chinese, which imposes a specific language on users without any opt-in or locale selection. The error message is also hard-coded in Chinese, indicating a language policy issue in the natural-language interface.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The stderr message for the missing-audio condition is emitted only in Chinese. Because the file does not offer a language choice or justify a locale restriction, this is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.