Back to skill

Security audit

视频翻译-免费版

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed video translation helper that sends user-provided videos or video URLs to a LuoJi translation API, with no evidence of hidden persistence, deception, or unrelated behavior.

Install only if you are comfortable sending the selected video file or video URL, plus your LuoJi API key in request headers, to the LuoJi online translation service. Use it for zh/en video translation tasks, not general text or document translation.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
78% confidence
Finding
The trigger condition is overly broad ('文本翻译、多语言转换、本地化处理时使用'), which could cause an agent to invoke this skill for unrelated translation or localization tasks outside video translation. In an agent environment with `read`, `write`, and `exec` tools, ambiguous activation increases the risk of accidental data routing to this external service and unintended handling of user content.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill asks users to upload video files or provide video URLs to a third-party service, but the early description does not prominently warn that content is transmitted off-platform. This can lead to inadvertent disclosure of sensitive videos, URLs, or embedded personal data because users may reasonably assume processing is local or agent-contained.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.