Back to skill

Security audit

Video Analysis Workflow 视频案例分析助手

Security checks for vulnerabilities and agentic risk

Overview

The skill’s video-analysis purpose is coherent, but its setup instructions include unaudited installation paths and unpinned dependency installs that users should review before running.

Install only if you are comfortable with a video workflow that downloads media and writes a structured local case library. Before running setup, verify or obtain the missing setup script from a trusted source, avoid ExecutionPolicy Bypass where possible, install dependencies in an isolated environment, and approve any browser-cookie access only for videos you are authorized to download.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:371
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:118
Finding

Unauditable Setup Script Executed with PowerShell Policy Bypass

Content
View full analysis
\scripts\setup-video-case-env.ps1 ``` The same command is documented for the Codex, Claude, and OpenClaw/Agents environments. ### Technical Analysis The initialization instructions direct the Agent to execute a PowerShell script using `-ExecutionPolicy Bypass`. This option suppresses the normal execution-policy restriction for that process, removing one defense that may otherwise block untrusted or unsigned scripts. The referenced `scripts/setup-video-case-env.ps1` file is not present in the audited project. Consequently, its implementation, download sources, dependency versions, integrity checks, and side effects cannot be reviewed. The documentation claims that this script prepares FFmpeg, Python 3.13, Whisper, and `yt-dlp`, but the package contains no corresponding implementation. The absent script also means that the documented setup process is incomplete as distributed. If a script is later obtained from another source or placed at the expected path, the instructions would execute that unaudited content while bypassing PowerShell's execution-policy checks. ### Attack Path 1. The Agent detects that the environment lacks required video-analysis dependencies. 2. It follows the first-use instructions in `SKILL.md`. 3. The expected setup script is supplied separately, restored from an unaudited source, or replaced at the referenced path. 4. The Agent invokes PowerShell with `-ExecutionPolicy Bypass`. 5. Malicious or compromised commands in the substituted script execute without execution-policy enforcement. 6. Those commands run with the privileges of the user who launched the Agent and may install additional components or modify the local environment. No malicious setup scrip ...[truncated 784 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README advertises downloading online videos and organizing outputs into a local case library, but the initial description does not prominently warn that using the skill may perform external network requests and create multiple local artifacts. Users may invoke it without understanding that it can download content, write folders/files, and potentially initiate installation flows, which is risky for privacy, policy compliance, and user consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list contains broad phrases like '参考视频', '视频策划', and '脚本模板' that can plausibly appear in ordinary user conversation, increasing the chance the skill activates outside clear user intent. In a skill that can download remote content and create local files, accidental invocation expands the attack surface and can lead to unintended network access or filesystem writes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The markdown trigger section lists short phrases such as “参考视频”, “视频策划”, and “视频案例” that are broad and could overlap with ordinary discussion about videos rather than an explicit request to invoke the skill. The file does not provide exclusion conditions or negative examples to clarify when these phrases should not activate the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill performs substantial local file writes, creates folders and reports, and may download source media, but it does not present a prominent upfront warning that these actions will modify the local filesystem. In agentic environments, insufficient disclosure can lead to unintended writes to sensitive directories, cluttering archives, or user confusion about where downloaded and generated artifacts are stored.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.