Back to skill

Security audit

Analyze Video By Qwen Free

Security checks for vulnerabilities and agentic risk

Overview

This skill is a remote video-analysis helper, but its trigger language is broader than its actual purpose and it does not clearly require consent before local video content is processed by DashScope.

Review before installing. Use it only for videos you are comfortable sending to Alibaba Cloud DashScope, avoid sensitive or regulated media unless you have approval, and configure credentials carefully because the documented key-check command may reveal the API key in terminal output or logs.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
95% confidence
Finding
The invocation text is overly broad, covering unrelated tasks such as video processing, audio editing, media conversion, and dubbing, even though the skill only performs basic video analysis. In an agent environment, such broad matching can cause the skill to be auto-selected for tasks outside its intended scope, increasing the chance that local files are read and sent to a remote API unexpectedly.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill states it analyzes local video files via DashScope but does not clearly warn users that the content of those local files will be transmitted to a third-party remote API. This can lead to unintentional disclosure of sensitive or regulated video data, especially because the skill is framed as handling local files and may be invoked automatically by an agent.

Static analysis

No suspicious patterns detected.