Back to skill

Security audit

Media Studio Metered

Security checks for vulnerabilities and agentic risk

Overview

This skill is openly designed for metered media generation and resale, but it gives agents unusually broad authority to initiate authentication and billing-related workflows with limited user control.

Install only if you intentionally want SettleMesh-mediated, metered media generation and resale. Before use, confirm the account, billing terms, session caching behavior, output retention period, and any end-user charging or markup; do not let the agent initiate login, uploads, paid renders, or payer-header billing unless you explicitly approve that action.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill explicitly tells the agent to automatically run authenticated login flows and open a browser without first obtaining clear user consent. This can trigger credentialed network actions, session creation, and external authorization flows unexpectedly, which is dangerous because the user may not realize the agent is initiating authentication or establishing a billable account session.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill promotes charging end users per render and markup-enabled resale without requiring an explicit billing warning or affirmative consent at the point of use. In an agent context, this creates a serious risk of unauthorized charges to third parties or the user, especially when combined with broad invocation language and automated execution guidance.

Static analysis

No suspicious patterns detected.