Back to skill

Security audit

watch-cli

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent video-analysis helper that clearly discloses its downloads, transcription upload, archive storage, and optional cookie use.

Install this only if you are comfortable with a CLI that downloads videos, keeps processed video artifacts and transcripts in a local archive, and uploads extracted audio to Kyma API for transcription by default. Do not opt into browser-cookie access unless you understand that it can use your local platform session for that specific run.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill explicitly advises invoking `watch` whenever a user provides a video URL and even when the URL is given with no clear task, which is broader than necessary. This can cause the agent to fetch and process external content without sufficiently specific user intent, increasing the chance of unnecessary network access, privacy exposure, and misuse on unrelated requests.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.