Back to skill

Security audit

视频

Security checks across malware telemetry and agentic risk

Overview

This is a media-generation skill with disclosed command examples and no hidden install, persistence, data theft, or destructive behavior found.

Before installing, understand that this skill may lead an agent to run local Python/media commands, read input scripts or image folders, write video outputs, and use any API key or TTS command you configure. Only use trusted script paths and TTS command templates, and review commands before execution.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The skill simultaneously presents itself as a pure Markdown/natural-language skill while elsewhere declaring exec capability and providing direct shell invocation examples. This mismatch can cause an agent or user to apply a lower-trust handling model than warranted, increasing the chance of unsafe command execution from untrusted inputs such as script paths or custom command templates.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation text says to use the skill whenever video/audio/media processing is needed, which is overly broad and lacks clear trigger boundaries or safety preconditions. In an agent setting, vague activation criteria can cause the skill to run in contexts the user did not explicitly intend, potentially leading to unnecessary file access or command execution.

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
The description states that the skill supports/uses Chinese interaction without clearly framing this as optional user preference. Forced language behavior can degrade transparency and user comprehension of prompts, parameters, and execution side effects, which is especially risky for a skill that may invoke commands.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.