Back to skill

Security audit

Ffmpeg Chinese Subtitle

Security checks for vulnerabilities and agentic risk

Overview

This is a local media subtitle helper with some packaging and example-code safety caveats, but no evidence of hidden access, persistence, credential use, or data exfiltration.

Install only in an environment where local media processing with ffmpeg is acceptable. Use Python packaging for Pillow, preferably with a pinned reviewed version, choose output paths carefully because files may be overwritten, and avoid using the optional concat helper with untrusted filenames or shared temporary directories.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
package.json:16
Finding

Ambiguous and Unbounded Third-Party Dependency Declaration

Content
View full analysis
=10.0.0" } ``` `SKILL.md:67-71`: ```text ## 依赖 Pillow>=10.0.0 ``` `README.md:54-58`: ```bash pip install Pillow ``` ### Technical Analysis The project requires the Python Pillow library but declares it inside an npm-style `package.json`. Python and npm use separate package registries, so an npm client does not treat this entry as the documented PyPI dependency. A user or automated system that runs `npm install` based on `package.json` could resolve an unintended npm package with the same name, or installation may fail depending on registry naming and validation behavior. The Python installation guidance also permits every Pillow release at or above version 10.0.0. There is no upper bound, lockfile, integrity hash, or reviewed dependency snapshot. Consequently, future releases are accepted without review. If the package or distribution channel is compromised, installation may execute untrusted package build or installation behavior with the invoking user's privileges. This issue is a supply-chain weakness rather than evidence that the currently documented Pillow package is malicious. ### Attack Path 1. A user or automated environment obtains the project. 2. The environment interprets `package.json` as an npm manifest and attempts to install its dependencies, or follows the unpinned `pip install Pillow` instruction. 3. In the npm case, the client may resolve a package from the wrong ecosystem. In the Python case, the resolver selects any future version satisfying `>=10.0.0`. 4. An attacker publishes or compromises the package selected through the ambiguous or unbounded declaration. 5. Package ...[truncated 486 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
example.py:79
Finding

Predictable Temporary Manifest Allows Symlink Overwrite and FFconcat Directive Injection

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill metadata does not declare any tool restrictions, yet the documented file structure and usage imply capabilities that write files and may invoke ffmpeg through a shell or subprocess. In an agent environment, missing scope declarations can allow broader-than-expected execution, increasing the chance of unintended file modification or command execution if the skill is invoked automatically.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are fairly generic terms related to subtitles and video processing, which can cause the skill to activate in broader contexts than intended. Overly broad invocation increases the risk that an agent routes unrelated user requests into a skill that can write files or launch media-processing commands, expanding exposure unnecessarily.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring states that Pillow draws subtitles and ffmpeg 'only' converts images to video to avoid encoding issues. In practice, the code uses ffprobe to inspect audio/video duration and ffmpeg to concatenate videos and mix background music, which directly contradicts the claimed limited role of ffmpeg.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code file contains docstrings and usage guidance only in Chinese, and later prints user-facing status messages in Chinese as well. Under the stated policy, forcing a specific language without offering a choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · example.py (reported line 19)May include surrounding context.

python
"""获取音频时长"""
    cmd = ["ffprobe", "-v", "error", "-show_entries", "format=duration",
           "-of", "default=noprint_wrappers=1:nokey=1", audio_path]
    result = subprocess.run(cmd, capture_output=True, text=True)
    try:
        return float(result.stdout.strip())
    except:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · example.py (reported line 115)May include surrounding context.

python
"""获取音频时长"""
    cmd = ["ffprobe", "-v", "error", "-show_entries", "format=duration",
           "-of", "default=noprint_wrappers=1:nokey=1", audio_path]
    result = subprocess.run(cmd, capture_output=True, text=True)
    try:
        return float(result.stdout.strip())
    except:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · example.py (reported line 75)May include surrounding context.

python
output_path
    ]
    
    result = subprocess.run(cmd, capture_output=True, text=True, encoding='utf-8', errors='replace')
    
    if result.returncode == 0:
        print(f"视频创建成功: {output_path}")

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes a solution focused on generating Chinese subtitles by drawing text with Pillow and using ffmpeg only for image-to-video conversion. However, the code also provides separate capabilities to concatenate multiple videos and add background music, which are broader video post-processing features not implied by the stated subtitle-generation scope.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
86% confidence
Finding

The code writes attacker-influenced paths into an ffmpeg concat list file using the concat demuxer format file '...' without escaping embedded quotes or special characters. A crafted filename containing a quote or newline can corrupt the list file and cause ffmpeg to read unintended files, making the behavior broader than the provided video_paths list.

Content

Scanner excerpt · example.py (reported line 100)May include surrounding context.

python
output_path
    ]
    
    subprocess.run(cmd, check=True, capture_output=True, encoding='utf-8', errors='replace')
    return output_path

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · example.py (reported line 131)May include surrounding context.

python
output_path
    ]
    
    subprocess.run(cmd, check=True, capture_output=True, encoding='utf-8', errors='replace')
    return output_path

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file documents functions that write output image and video files via output_path, but it does not warn users that these operations create or may replace files on disk. For markdown files, SQP-2 applies when user-impacting file operations are described without disclosure about effects on user data or system state.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The top-level docstring explicitly defines the module as a Chinese subtitle solution and the function documentation repeatedly states that it adds Chinese subtitles. This creates a language-specific constraint in natural-language instructions without offering a user choice or documenting that the skill is region-specific by design.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The description and several keywords specify the skill in Chinese only, which can amount to a language/locale policy issue when no user opt-in or alternative language is provided. Nothing in the manifest indicates that the Chinese-only presentation is optional or justified as a region-specific tool.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.