T08 · Insecure Dependencies
- Location
SKILL.md:371- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s video-analysis purpose is coherent, but its setup instructions include unaudited installation paths and unpinned dependency installs that users should review before running.
Install only if you are comfortable with a video workflow that downloads media and writes a structured local case library. Before running setup, verify or obtain the missing setup script from a trusted source, avoid ExecutionPolicy Bypass where possible, install dependencies in an isolated environment, and approve any browser-cookie access only for videos you are authorized to download.
SKILL.md:371Unpinned Third-Party Dependency Installation
SKILL.md:118Unauditable Setup Script Executed with PowerShell Policy Bypass
The README advertises downloading online videos and organizing outputs into a local case library, but the initial description does not prominently warn that using the skill may perform external network requests and create multiple local artifacts. Users may invoke it without understanding that it can download content, write folders/files, and potentially initiate installation flows, which is risky for privacy, policy compliance, and user consent.
The trigger list contains broad phrases like '参考视频', '视频策划', and '脚本模板' that can plausibly appear in ordinary user conversation, increasing the chance the skill activates outside clear user intent. In a skill that can download remote content and create local files, accidental invocation expands the attack surface and can lead to unintended network access or filesystem writes.
The markdown trigger section lists short phrases such as “参考视频”, “视频策划”, and “视频案例” that are broad and could overlap with ordinary discussion about videos rather than an explicit request to invoke the skill. The file does not provide exclusion conditions or negative examples to clarify when these phrases should not activate the skill.
The skill performs substantial local file writes, creates folders and reports, and may download source media, but it does not present a prominent upfront warning that these actions will modify the local filesystem. In agentic environments, insufficient disclosure can lead to unintended writes to sensitive directories, cluttering archives, or user confusion about where downloaded and generated artifacts are stored.
No suspicious patterns detected.