Back to skill

Security audit

Lh Video Gen Paid

Security checks for vulnerabilities and agentic risk

Overview

This skill is a video-generation workflow, but it asks agents to run local commands and batch file operations with incomplete scoping and repeated unsafe administrator guidance.

Review this skill before installing. Use it only in a restricted workspace with non-sensitive media, explicit output directories, and reviewed scripts. Do not run its workflows as root or administrator, and confirm any TTS, translation, or platform integration before sending business or private content to external services.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:443
Finding

Generic Administrator Execution Guidance Violates Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 443, 461, and 482
Vulnerability Type: Unnecessary privilege escalation guidance
Risk Level: Medium

Relevant code snippet (English rendering of the repeated table row):

text
| Insufficient permissions | The current user lacks read/write permissions | Check file permissions and run as administrator |

Technical Analysis

The Skill repeats a recommendation to run operations as an administrator whenever the current user lacks file read or write permissions. This is an unsafe generic remedy because batch video generation, media processing, and writing output files ordinarily do not require system-wide administrative privileges.

The document also instructs users to execute local programs such as init_project.py, batch_generate.py, and retry commands. These scripts are not included in the audited package, so their implementation and trustworthiness cannot be verified. If users apply the administrator recommendation while executing an untrusted, replaced, or vulnerable script, that process receives permissions beyond those legitimately required for video processing.

The issue is a violation of least privilege rather than an automatic privilege-escalation exploit: the Skill does not itself elevate privileges or bypass an operating-system access control. Exploitation depends on a user following the instruction and launching affected tooling in an elevated context.

Attack Path

  1. An attacker supplies, replaces, or modifies a referenced local script such as batch_generate.py or init_project.py.
  2. The script or selected output path produces a permission-denied error, either naturally or intentionally.
  3. The user follows the repeated troubleshooting guidance and reruns the relevant operation as an administrator.
  4. The attacker-controlled or vulnerable script executes with elevated operating-system permissions.
  5. The script can access o ...[truncated 842 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove all three recommendations to run as an administrator from lines 443, 461, and 482.
  2. Replace them with least-privilege troubleshooting steps:
    • Confirm that the input and output paths are correct.
    • Use a working directory owned by the current user.
    • Inspect ownership and permissions on only the affected file or directory.
    • Grant the minimum required read or write permission to the current user.
    • Avoid broad recursive permission changes and world-writable directories.
  3. Explicitly state that video generation and media processing scripts must not be run as root or administrator.
  4. If a separately reviewed installation action genuinely requires elevation, isolate it from normal rendering operations, document the exact privileged command, and explain why elevation is necessary.
  5. Package or identify the expected scripts with integrity information so users can verify them before execution.
  6. Recommend execution inside a sandbox, container, or restricted service account with access only to required media assets and output directories.
  7. Add a warning that permission errors must not be resolved by elevating unknown or user-supplied scripts.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation guidance uses very broad productivity-oriented trigger language, encouraging use in loosely related automation scenarios rather than narrowly scoped video-generation tasks. In agent environments, overbroad triggers can cause accidental activation of a skill with read/write/exec capabilities in contexts the user did not intend, increasing the chance of unsafe command execution or file operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The multilingual and TTS workflow sections discuss translation and voice services without clearly warning that content may be transmitted to external APIs or cloud TTS providers. This can expose sensitive scripts, brand assets, or business data to third parties without informed consent, especially in enterprise batch workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill describes batch generation and writing output files but does not clearly warn that it may create, overwrite, or populate many local files and directories. In a tool-using agent, this omission can lead to destructive or unexpected filesystem changes, especially during bulk operations where mistakes scale quickly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill omits a clear warning that it invokes local commands and external tooling such as Python and FFmpeg through exec-capable workflows. Because the skill explicitly advertises read/write/exec capabilities, failure to disclose command execution risk can cause users or agents to run local processes without understanding the security implications, dependency trust, or system impact.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documented input/output contract describes a generic text-processing interface and JSON response shape that does not match the skill's claimed purpose of batch video generation. This mismatch can cause an agent or user to invoke the skill with incorrect assumptions, leading to unsafe automation decisions, misrouted data, or unintended downstream handling of outputs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill states both that no extra API key is required and elsewhere that some features do require platform API keys, creating contradictory security guidance. This can lead users to mishandle secrets, configure keys in unsafe ways, or unintentionally send data to third-party services without understanding the trust boundary.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The output example uses fields like result, word_count, and template_used: reviewer, which are characteristic of a text-processing or review skill rather than a short-video generator. This contradicts the surrounding documentation that the skill generates branded batch videos and may mislead users about what the skill actually returns.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.