Back to skill

Security audit

Video Editing Tool Free

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a video-editing monetization guide, but it asks for shell execution and broad media-task activation that do not fit its stated Markdown-only purpose.

Review this skill before installing. It does not show malicious behavior or hidden scripts, but it should not need shell execution for a Markdown monetization guide, and its trigger scope should be narrowed to business guidance such as pricing, client acquisition, workflows, and launch planning.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill claims it is pure Markdown and does not require exec, yet the manifest grants exec and the troubleshooting section instructs use of shell commands such as ping. This inconsistency can mislead users and hosting agents into trusting a non-executing skill while still exposing command-execution capability, increasing the chance of unnecessary tool use or abuse.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
Granting shell execution to a monetization-guidance skill violates least-privilege because its described function is strategic guidance, not system administration or local automation. Unneeded exec access broadens the attack surface: if the skill is invoked in an agentic environment, prompt injection or misuse could cause arbitrary local command execution unrelated to the business-guidance purpose.

Description-Behavior Mismatch

Medium
Confidence
84% confidence
Finding
The skill is described as a video-editing monetization framework, but its trigger conditions broaden applicability to video processing, audio editing, media conversion, and voice generation. This scope mismatch can cause the skill to activate in contexts beyond its documented competence, potentially leading an agent to use inappropriate tools or workflows under misleading assumptions.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger condition is overly broad and inconsistent with the skill’s real purpose, making it likely to be auto-selected for many unrelated media tasks. In an agent platform, this can route user requests into a skill with unnecessary exec permission and inaccurate instructions, creating a meaningful security and reliability risk through mis-triggering.

Static analysis

No suspicious patterns detected.