Back to skill

Security audit

Natural Language Video Search

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but its setup installs mutable external code and dependencies, so users should review it before installing.

Install only if you are comfortable reviewing or trusting the external sentrysearch repository at install time. Use a dedicated environment, pin a known commit if possible, limit the folders provided for indexing, avoid sensitive footage unless you accept Gemini API processing, and be careful sharing clips with GPS or telemetry overlays.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:35
Finding

Unpinned Remote Repository Retrieval and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 35–39
Vulnerability Type: Mutable external code retrieval and execution
Risk Level: High

bash
git clone https://github.com/ssrajadh/sentrysearch.git
cd sentrysearch
uv sync

Technical Analysis

The setup instructions clone the current default branch of an external Git repository without specifying an immutable commit hash or verified release tag. They then run uv sync, which processes the remotely supplied project configuration and installs its dependencies.

Consequently, the code installed by users can differ from the code that existed when this Skill was audited. The Skill package contains only SKILL.md; it does not include the application source, a locally reviewable lockfile, integrity hashes, or signature-verification instructions. A malicious or compromised upstream revision can therefore become the effective payload without requiring any change to the audited Skill.

Although uv sync also creates dependency supply-chain exposure, the primary issue is remote payload retrieval: the mutable repository determines which application code and dependency configuration are installed.

Attack Path

  1. An attacker compromises the upstream repository, a maintainer account, or the repository's default branch.
  2. The attacker adds malicious application code or modifies dependency declarations to reference a malicious component.
  3. A user follows the documented setup procedure and clones the mutable default branch.
  4. The user runs uv sync, causing the attacker-controlled project and dependencies to be installed.
  5. The malicious payload executes during installation or when the user subsequently invokes sentrysearch.
  6. The payload operates with the invoking user's privileges and may access resources available to that user.

Impact Assessment

Successful exploitation can result in arbitrary code execution under the account running the installation or application. Access ...[truncated 557 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the mutable clone instruction with an immutable, reviewed commit:
    bash
    git clone https://github.com/ssrajadh/sentrysearch.git
    cd sentrysearch
    git checkout --detach <reviewed-full-commit-hash>
    
  2. Prefer a signed release artifact and document verification of its signature and cryptographic checksum before installation.
  3. Include a reviewed dependency lockfile and require locked or frozen installation so dependency resolution cannot silently select newer versions.
  4. Verify package hashes where supported and reject dependencies that do not match approved integrity metadata.
  5. Review the pinned application source, build configuration, installation hooks, and complete transitive dependency graph.
  6. Run installation and video processing in a sandbox or dedicated low-privilege environment with access limited to explicitly selected footage and output directories.
  7. Supply the Gemini credential only at runtime, restrict its API permissions and quota where possible, and avoid exposing unrelated credentials to the process.
  8. Establish a controlled update procedure in which new upstream revisions are reviewed and assigned a new verified commit or release before users are instructed to upgrade.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explains local indexing behavior but does not clearly warn that video chunks are uploaded to the Gemini API for embedding, which can expose sensitive footage to a third-party service. In the context of dashcam and security camera content, this omission is significant because users may unknowingly transmit personally sensitive, confidential, or surveillance data off-device.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Tesla overlay feature can burn GPS coordinates, location names, speed, and turn-signal state directly into exported clips, but the skill does not prominently warn that this may expose sensitive travel patterns or home/work locations when clips are shared. Because the skill is designed for dashcam footage, the context increases the risk that real-world personally identifying location data will be embedded in output artifacts.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The trigger guidance says the skill applies when a user asks to "index or organize video footage for search," which is broader and less specific than the concrete command patterns elsewhere in the file. Without exclusions or clearer boundaries, this could overlap with more general video-management requests and cause unintended invocation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.