Back to skill

Security audit

Kre Video Translator

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims: it extracts audio from a user-provided media file, sends it to KreTrans for subtitle translation, and writes an SRT file locally.

Install this only if you are comfortable sending extracted audio and filename/language metadata from the media you translate to KreTrans. Avoid using it on confidential recordings unless you have reviewed KreTrans privacy and retention terms, and prefer installing dependencies in a virtual environment with pinned versions when possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/setup.md:20
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: references/setup.md, line 20
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

Vulnerable Code Snippet:

markdown
- Install the Python package `requests` before the first run, for example: `python -m pip install requests`

Technical Analysis

The documented installation command resolves and installs whichever requests release is selected by the active Python package index at installation time. It provides neither a reviewed version constraint nor an integrity hash. The effective dependency can therefore change after the Skill has been audited.

Although requests is a legitimate and correctly named package, this installation practice does not protect against a compromised upstream release, compromised package index, or attacker-controlled package mirror configured in the user's environment. Python package installation may execute build or installation logic, and the installed package subsequently executes code when imported by scripts/translate.py.

Attack Path

  1. An attacker compromises a compatible package release, the configured package index, or a package mirror used by the victim.
  2. The user follows the documented command:
    bash
    python -m pip install requests
    
  3. pip resolves and installs the compromised artifact because no reviewed version or hash is enforced.
  4. Malicious code can execute during package installation or when scripts/translate.py imports requests.
  5. The malicious dependency runs in the translation process and can access process data, files available to the user, media being processed, and the KRETRANS_API_KEY environment variable.

Impact Assessment

Successful exploitation could permit arbitrary code execution with the privileges of the user running pip or the translation script. The scope may include theft of the KreTrans API credential, access to local media submitte ...[truncated 283 chars]

Remediation
View remediation

Remediation Suggestions

  1. Add a dependency manifest containing an explicitly reviewed requests version.
  2. Generate and verify cryptographic hashes for the package and all transitive dependencies.
  3. Require hash verification during installation, for example:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  4. Prefer binary wheels from a trusted, explicitly configured package index where practical.
  5. Review and update pinned dependencies through a controlled process that includes vulnerability scanning and testing.
  6. Recommend installation inside an isolated virtual environment under a non-privileged account.
  7. Avoid instructing users to run package installation with administrator or root privileges.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (11)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/translate.py (reported line 165)May include surrounding context.

python
return (
        "ffmpeg was not found. Install it first.\n"
        "Linux examples:\n"
        "Debian/Ubuntu: sudo apt update && sudo apt install -y ffmpeg\n"
        "Fedora: sudo dnf install -y ffmpeg\n"
        "Arch: sudo pacman -S ffmpeg"
    )

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill invokes shell commands, reads environment variables, writes files, and performs network operations, but it does not declare any explicit tool scope such as permissions or allowed-tools. That omission weakens least-privilege controls and can let an agent execute broader capabilities than reviewers or runtime policy expect, especially because the workflow includes downloading remote content and invoking local interpreters.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The skill explicitly uploads extracted audio and metadata such as filenames and language settings to a third-party API. This is a real data exfiltration boundary: while it appears necessary for the service's function, it can expose sensitive media contents and contextual metadata if used on private files without strong consent and disclosure.

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
- `aria2c`

`translate.py` only accepts local file input.
The script sends requests to `https://api.kretrans.com/v1/api`.
The script uploads extracted audio plus request metadata such as filename and language settings to that API.

## Python Launcher

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/setup.md (reported line 30)May include surrounding context.

md
DOCS_URL = "https://kretrans.com/api-docs"
API_KEY_MANAGEMENT_URL = "https://kretrans.com/console#api-management"
API_KEY_ENV_NAME = "KRETRANS_API_KEY"
API_BASE_URL = "https://api.kretrans.com/v1/api"
DEFAULT_CREATE_TIMEOUT_SECONDS = 600
DEFAULT_POLL_TIMEOUT_SECONDS = 30
DEFAULT_POLL_INTERVAL_SECONDS = 15

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/translate.py (reported line 32)May include surrounding context.

python
DOCS_URL = "https://kretrans.com/api-docs"
API_KEY_MANAGEMENT_URL = "https://kretrans.com/console#api-management"
API_KEY_ENV_NAME = "KRETRANS_API_KEY"
API_BASE_URL = "https://api.kretrans.com/v1/api"
DEFAULT_CREATE_TIMEOUT_SECONDS = 600
DEFAULT_POLL_TIMEOUT_SECONDS = 30
DEFAULT_POLL_INTERVAL_SECONDS = 15

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/translate.py (reported line 165)May include surrounding context.

python
return (
        "ffmpeg was not found. Install it first.\n"
        "Linux examples:\n"
        "Debian/Ubuntu: sudo apt update && sudo apt install -y ffmpeg\n"
        "Fedora: sudo dnf install -y ffmpeg\n"
        "Arch: sudo pacman -S ffmpeg"
    )

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/translate.py (reported line 166)May include surrounding context.

python
return (
        "ffmpeg was not found. Install it first.\n"
        "Linux examples:\n"
        "Debian/Ubuntu: sudo apt update && sudo apt install -y ffmpeg\n"
        "Fedora: sudo dnf install -y ffmpeg\n"
        "Arch: sudo pacman -S ffmpeg"
    )

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/translate.py (reported line 167)May include surrounding context.

python
return (
        "ffmpeg was not found. Install it first.\n"
        "Linux examples:\n"
        "Debian/Ubuntu: sudo apt update && sudo apt install -y ffmpeg\n"
        "Fedora: sudo dnf install -y ffmpeg\n"
        "Arch: sudo pacman -S ffmpeg"
    )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/translate.py (reported line 196)May include surrounding context.

python
"128k",
        str(output_file),
    ]
    completed = subprocess.run(
        command,
        stdout=subprocess.PIPE,
        stderr=subprocess.PIPE,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script extracts audio from a local media file and uploads it to api.kretrans.com, but it does not present an explicit warning or confirmation at the point of transmission. In a local-file processing skill, users may reasonably expect offline processing, so silent exfiltration of media-derived content can expose sensitive speech or confidential recordings.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The argument parser sets --target-language to zh by default, causing the skill to force a specific locale when the user does not choose one. This is a natural-language policy concern because it imposes a language preference rather than asking the user or remaining neutral.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.