Back to skill

Security audit

srt2md

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent SRT-to-Markdown helper, but users should know it may search the web using terms extracted from subtitles.

Install only if you are comfortable with a workflow that reads your supplied SRT file, writes converted TXT and Markdown outputs, and may use extracted terms for web searches. For confidential subtitles, ask the agent to run only the local conversion and skip search enrichment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest promises a complete in-session SRT-to-document workflow, but the documented behavior only clearly implements format conversion while implying additional analysis, enrichment, and report generation steps. This mismatch is dangerous because users may authorize the skill under false assumptions about what it will do, what data it will process, and whether it will perform external research.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger conditions are overly broad and mandate use whenever users mention SRT, subtitles, or turning videos into notes. Overbroad auto-invocation increases the chance the skill will process unrelated or sensitive content without sufficient user intent, especially because the workflow can proceed to analysis and web search.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
81% confidence
Finding

The skill documents file reading and writing behavior but does not declare any tool scope or permissions boundaries. This weakens least-privilege controls and can allow the skill to access or modify files more broadly than users or the platform may expect.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The core description presents the skill as an SRT-to-Markdown conversion workflow. Yet the body of the skill defines a separate '搜索补充' phase that gathers external sources and URLs, turning the output into a researched article/report rather than a straightforward subtitle-to-document conversion.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill claims processing is completed entirely with built-in session capabilities, but the workflow later includes web search and calling another skill. This is a transparency and data-handling issue because transcript-derived concepts may be sent outside the narrowly described processing path without clear user awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Phase three performs web searches using concepts and entities extracted from subtitles, but the skill description does not warn users that transcript-derived queries may be sent to search services. This creates a privacy and confidentiality risk, particularly if subtitles contain unpublished, personal, or sensitive material.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill’s stated purpose is converting SRT subtitles into structured Markdown, but this file expands scope to active external web searching and source aggregation. That creates unnecessary data egress and tool-use risk, because subtitle content may be sent to third-party search providers and the agent may pull in untrusted external content that can influence the final output beyond the user’s uploaded file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The guidance prescribes Chinese-specific engines for Chinese content and specific regional/international engines for English content as the default behavior. This is a natural-language locale policy constraint presented without user opt-in or an explicit choice mechanism, which can violate language/locale flexibility requirements.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

A skill framed as converting subtitle files into readable documents would ordinarily parse, analyze, and format the provided content. Delegating to another search skill introduces an additional capability—cross-skill web research orchestration—that is not clearly declared in the manifest as part of the skill's scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown template uses Chinese headings and instructions throughout, with no indication that users may choose another language or locale. Under the policy rule, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.