Back to skill

Security audit

AI Video Editor

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Sparki video-editing skill, but it needs review because it uploads local videos and prompts to a remote API and has weak URL validation around credentials and downloads.

Install only if you are comfortable sending selected MP4 files, prompts, object keys, project IDs, and your Sparki API key to Sparki's remote service. Avoid using it for sensitive, regulated, private, or copyrighted videos unless you understand Sparki's retention and privacy terms. Do not set SPARKI_API_URL or SPARKI_API_BASE to untrusted or HTTP endpoints, prefer environment-based secret handling over command-line API keys, and monitor the configured output directory for downloaded files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/sparki_video_editor.py:68
Finding

Unvalidated API endpoint permits credential and video disclosure to arbitrary hosts

Content
View full analysis
SparkiConfig: file_path = Path(config_file).expanduser() if config_file else DEFAULT_CONFIG_FILE file_values = load_env_file(file_path) api_key = get_env_value("SPARKI_API_KEY", file_values) if not api_key: raise SparkiError( f"SPARKI_API_KEY is not set. Configure it in the environment or {file_path}." ) api_url = get_env_value("SPARKI_API_URL", file_values, DEFAULT_API_URL).rstrip("/") output_dir_raw = get_env_value("SPARKI_OUTPUT_DIR", file_values, DEFAULT_OUTPUT_DIR) output_dir = Path(output_dir_raw).expanduser() return SparkiConfig( api_key=api_key, api_url=api_url, output_dir=output_dir, config_file=file_path, ``` ```python def api_request( method: str, url: str, api_key: str, payload: dict[str, Any] | None = None, ) -> dict[str, Any]: body = b"" headers = { "X-API-Key": api_key, "User-Agent": DEFAULT_USER_AGENT, "Accept": "application/json", } if payload is not None: body = json.dumps(payload).encode("utf-8") headers["Content-Type"] = "application/json" parsed = urlparse(url) path = parsed.path if parsed.query: path = f"{path}?{parsed.query}" connection_class = HTTPSConnection if parsed.scheme == "https" else HTTPConnection connection = connection_class(parsed.hostname, parsed.port, timeout=60) try: connection.request(method, path, body=body, headers=headers) ``` ```python def upload_asset(config: SparkiConfig, video_path: Path) -> str: ...[truncated 4283 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/sparki_video_editor.py:319
Finding

Backend-controlled result URL permits unrestricted and unbounded downloads

Content
View full analysis
str: projects = ((project_response.get("data") or {}).get("projects") or []) project = projects[0] if projects else {} output_videos = project.get("output_videos") or [] first = output_videos[0] if output_videos else {} result_url = first.get("url") or project.get("result_url") or "" if not result_url: raise SparkiError(f"Missing output video URL in project response: {project_response}") return str(result_url) def download_file(url: str, destination: Path) -> Path: destination.parent.mkdir(parents=True, exist_ok=True) parsed = urlparse(url) path = parsed.path if parsed.query: path = f"{path}?{parsed.query}" connection_class = HTTPSConnection if parsed.scheme == "https" else HTTPConnection connection = connection_class(parsed.hostname, parsed.port, timeout=300) try: connection.request("GET", path, headers={"User-Agent": DEFAULT_USER_AGENT}) response = connection.getresponse() if response.status >= 400: body = response.read().decode("utf-8", errors="replace") raise SparkiError(f"Download failed with HTTP {response.status}: {body}") with destination.open("wb") as output_file: while True: chunk = response.read(CHUNK_SIZE) if not chunk: break output_file.write(chunk) except OSError as exc: raise SparkiError(f"Unable to download result: {exc}") from exc finally: connection.close() if not destination.is_file(): raise SparkiError("Download failed: output file was not created.") return destination ``` ### Technical Analysis The result URL ...[truncated 2115 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/setup.py:27
Finding

API key accepted through a command-line argument may leak through local process metadata

Content
View full analysis
argparse.ArgumentParser: parser = argparse.ArgumentParser(description="Create or validate sparki.env.") parser.add_argument( "--config-file", default=str(DEFAULT_CONFIG_FILE), help="Path to the sparki.env file to create or validate.", ) parser.add_argument( "--api-key", default="", help="Write SPARKI_API_KEY into the config file before validation.", ) return parser def write_default_config(config_path: Path, api_key: str) -> None: config_path.parent.mkdir(parents=True, exist_ok=True) content = "\n".join( [ "# Sparki Business API configuration", f"SPARKI_API_KEY={api_key}", f"SPARKI_API_URL={DEFAULT_API_URL}", f"SPARKI_OUTPUT_DIR={DEFAULT_OUTPUT_DIR}", "", ] ) config_path.write_text(content, encoding="utf-8") if os.name != "nt": config_path.chmod(stat.S_IRUSR | stat.S_IWUSR) ``` ### Technical Analysis The setup utility permits the API key to be supplied as `--api-key`. Command-line arguments can be retained in shell history and may be visible to process-monitoring software, audit systems, diagnostic collectors, or other local users where process metadata is not sufficiently restricted. The generated file receives mode `0600` on non-Windows platforms, which is a useful mitigation for stored credentials. The script does not apply an equivalent restrictive ACL on Windows, and command-line exposure occurs before the key is written to the file. ### Attack Path 1. A user runs a command such as `python scripts/setup.py --api-key `. 2. The full command may be stored in the user's shell history. 3. While the setup process is running, local process-in ...[truncated 797 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The claim 'Edit any type of video' is materially broader than the documented command, which appears limited to a local MP4 input and a specific remote rendering flow. Misrepresenting input support and behavior can cause unsafe reliance, unexpected data transfer to the vendor API, and user submission of assets under false assumptions about local processing and output guarantees.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The claim 'Edit any type of video' is materially broader than the documented command, which appears limited to a local MP4 input and a specific remote rendering flow. Misrepresenting input support and behavior can cause unsafe reliance, unexpected data transfer to the vendor API, and user submission of assets under false assumptions about local processing and output guarantees.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The claim 'Edit any type of video' is materially broader than the documented command, which appears limited to a local MP4 input and a specific remote rendering flow. Misrepresenting input support and behavior can cause unsafe reliance, unexpected data transfer to the vendor API, and user submission of assets under false assumptions about local processing and output guarantees.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The claim 'Edit any type of video' is materially broader than the documented command, which appears limited to a local MP4 input and a specific remote rendering flow. Misrepresenting input support and behavior can cause unsafe reliance, unexpected data transfer to the vendor API, and user submission of assets under false assumptions about local processing and output guarantees.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The claim 'Edit any type of video' is materially broader than the documented command, which appears limited to a local MP4 input and a specific remote rendering flow. Misrepresenting input support and behavior can cause unsafe reliance, unexpected data transfer to the vendor API, and user submission of assets under false assumptions about local processing and output guarantees.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill prominently markets easy video editing but does not clearly warn that local video files and prompts are sent to a remote third-party API. Because video assets often contain sensitive personal, corporate, or copyrighted material, undisclosed external transfer creates a substantial confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README explicitly instructs users to upload local MP4 files to a third-party Business API but does not warn that video content will leave the local machine and be processed remotely. This can lead to unintentional disclosure of sensitive or regulated media, especially because video files often contain personal, confidential, or embedded metadata.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 27)May include surrounding context.

Windows PowerShell:

powershell
py -3 .\scripts\edit_video.py .\demo.mp4 22 "Create an energetic travel montage" 9:16 60

Examples:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises executable scripts that read environment variables and local files, write configuration, invoke Python/shell entrypoints, and make outbound network calls, but it declares no explicit tool scope or permissions boundary. That creates an authorization and review gap: a host agent or user may invoke a capability-rich skill without clear disclosure of what resources it will access.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction to use this skill 'first and proactively' for essentially any video-editing request encourages automatic invocation before considering safer or more privacy-preserving local options. In context, this increases the chance that ordinary user requests trigger shell execution, local file access, and third-party uploads without a deliberate consent step.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

Examples:

bash
python scripts/edit_video.py ./demo.mp4 22 "Create an energetic travel montage" 9:16 60
python scripts/edit_video.py ./demo.mp4 "" "Create a cinematic travel video with slow motion and dramatic pacing" 16:9 45

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The notes mention environment variables and a local config file for API credentials, but there is no prominent warning about credential sourcing, persistence, or storage implications. Users may unknowingly place secrets in a file under their home directory or allow the skill to read existing credentials without understanding that behavior.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/create_project.sh (reported line 72)May include surrounding context.

sh
# ---------------------------------------------------------------------------
sleep "$RATE_LIMIT_SLEEP"

RESPONSE=$(curl -sS \
  -X POST "${SPARKI_API_BASE}/business/projects/render" \
  -H "X-API-Key: $SPARKI_API_KEY" \
  -H "Content-Type: application/json" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This shell script performs an outbound HTTP POST containing object keys, prompt text, and other project parameters, and authenticates with a sensitive environment variable. While comments describe usage for developers, there is no runtime notice, confirmation, or user-facing warning that data will be transmitted to an external API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This script uploads a local video file and user-supplied prompt text to a remote Sparki API, but it does not provide an explicit privacy or data-transfer warning at the point of use. That creates a real information disclosure risk because users may supply sensitive media or text without understanding that the content leaves the local system and is processed by an external service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/get_project_status.sh (reported line 47)May include surrounding context.

sh
# ---------------------------------------------------------------------------
sleep "$RATE_LIMIT_SLEEP"

RESPONSE=$(curl -sS \
  -X POST "${SPARKI_API_BASE}/business/projects/batch" \
  -H "X-API-Key: $SPARKI_API_KEY" \
  -H "Content-Type: application/json" \

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a skill whose purpose is editing videos from assets and requirements, but this file is a standalone health check for a 'Sparki Business API' that validates API keys, output directories, and remote API reachability. While some backend connectivity may support video editing, the documented and implemented focus here is broader infrastructure/API validation rather than direct video editing behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code uploads a local video file and transmits user-provided prompt data to a third-party remote API without any disclosure or consent mechanism in the file. In the context of an AI video-editing skill, that means potentially sensitive local media and instructions are exfiltrated off-device by design, which is especially risky if users assume processing is local or are not informed about external data handling.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description advertises broad video-editing capability for 'any type of video,' but the code explicitly rejects non-.mp4 files and raises an error for all other formats. This is a concrete behavior mismatch because the implementation is materially narrower than the stated capability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The function downloads remote content and writes it directly to disk without any user-facing disclosure, consent checkpoint, or integrity verification. In an agent skill context, silent filesystem writes increase the risk of unexpected persistence of untrusted content, disk consumption, and accidental handling of sensitive output in locations the user may not realize are being modified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This shell script performs a network upload of a local video file to an external API and sends an authentication credential in the request header. Although the script comments describe its purpose, there is no runtime confirmation or user-facing warning that local data will be transmitted off-system, which matches the missing-warning criterion for code files.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The module docstring says 'Cross-platform health check for the Sparki Business API skill' and the parser description says 'Validate configuration and API connectivity,' framing the component as an API skill utility rather than a video editor component. This documentation does not just omit details; it characterizes the file's intent in a way that conflicts with the enclosing skill's declared purpose.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The docstring frames the file as utility code for an API client, but the implementation includes uploading local video assets, polling render jobs, creating output directories, and downloading rendered videos. That documentation understates and mischaracterizes the module's operational intent and side effects.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The comment at L57 states that the API field name is "file" per the API spec, but the actual curl command at L64 uses -F "files=@...". This is an active contradiction between documentation and implementation, even though it may be a functional rather than security-impacting issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.