Back to skill

Security audit

Camera

Security checks for vulnerabilities and agentic risk

Overview

This camera skill does what it says at a high level, but it can activate webcams, record short videos, and leave privacy-sensitive files in predictable /tmp paths without requiring explicit confirmation.

Review this before installing. It is not evidence of malware or exfiltration, but it gives an agent practical camera-capture instructions. Use it only if you are comfortable with webcam activation after explicit user intent, and consider revising it to require confirmation, use private per-run temporary directories, and delete warmup videos automatically.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:21
Finding

Predictable Temporary Files Allow File Clobbering and Capture Collisions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 21–29
Vulnerability Type: Predictable temporary files with forced overwrite
Risk Level: Medium

Evidence

bash
ffmpeg -loglevel error -f avfoundation -framerate 30 -i "0" -t 5 -y /tmp/brio_warmup.mp4 && \
ffmpeg -loglevel error -sseof -0.5 -i /tmp/brio_warmup.mp4 -frames:v 1 -update 1 -y /tmp/brio.jpg
bash
ffmpeg -loglevel error -f avfoundation -pixel_format nv12 -framerate 30 -i "1" -t 5 -y /tmp/facetime_warmup.mp4 && \
ffmpeg -loglevel error -sseof -0.5 -i /tmp/facetime_warmup.mp4 -frames:v 1 -update 1 -y /tmp/facetime.jpg

Technical Analysis

The capture commands use fixed, globally predictable paths under /tmp and instruct ffmpeg to overwrite existing destinations with -y. The commands do not create a private temporary directory, verify file ownership, reject symbolic links, or generate unique filenames.

Concurrent skill invocations can overwrite or mix one another's files. A local attacker able to create entries at the predictable paths before invocation may also attempt a symbolic-link or path-prepositioning attack. If the output-opening behavior follows an attacker-controlled link, a file writable by the skill's operating-system account could be truncated or replaced. The attack remains limited by the privileges of the account running ffmpeg; the commands do not independently provide privilege escalation.

Attack Path

  1. A local attacker predicts one of the documented paths, such as /tmp/brio.jpg or /tmp/brio_warmup.mp4.
  2. Before the skill runs, the attacker creates a conflicting filesystem entry or symbolic link at that path.
  3. A user invokes the camera skill.
  4. ffmpeg -y opens the predictable destination without validating that it is a newly created regular file owned by the invoking account.
  5. Depending on filesystem and ffmpeg behavior, the destination may be overwritten, redir ...[truncated 580 chars]
Remediation
View remediation

Remediation Suggestions

  • Create a unique private working directory with mktemp -d for every invocation.
  • Set restrictive permissions with umask 077 and directory mode 0700.
  • Place both intermediate videos and final images inside that private directory.
  • Avoid blindly overwriting existing paths. Ensure output files do not already exist and are regular files owned by the invoking account.
  • Where possible, use APIs or file-opening controls that reject symbolic links, such as O_NOFOLLOW semantics.
  • Serialize access to each physical camera or use invocation-specific filenames to prevent concurrent-run collisions.
  • Install a shell trap that reliably removes all temporary artifacts on success, failure, or interruption.
  • Move or copy the final image to a caller-approved destination only after capture and validation.

other

Warning
Location
SKILL.md:21
Finding

Unnecessary Retention of Privacy-Sensitive Webcam Video

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 21–38
Vulnerability Type: Privacy-sensitive data over-retention
Risk Level: Medium

Evidence

bash
ffmpeg -loglevel error -f avfoundation -framerate 30 -i "0" -t 5 -y /tmp/brio_warmup.mp4 && \
ffmpeg -loglevel error -sseof -0.5 -i /tmp/brio_warmup.mp4 -frames:v 1 -update 1 -y /tmp/brio.jpg
bash
ffmpeg -loglevel error -f avfoundation -pixel_format nv12 -framerate 30 -i "1" -t 5 -y /tmp/facetime_warmup.mp4 && \
ffmpeg -loglevel error -sseof -0.5 -i /tmp/facetime_warmup.mp4 -frames:v 1 -update 1 -y /tmp/facetime.jpg
markdown
## Output
- Photos saved to `/tmp/brio.jpg` and `/tmp/facetime.jpg`
- Warmup videos in `/tmp/*_warmup.mp4` (can be deleted)
- Photos are ~80-100KB each

Technical Analysis

Although the skill's declared purpose is to capture a photograph, each invocation records five seconds of webcam video and retains that intermediate recording after extracting a frame. The documentation merely states that the videos “can be deleted”; deletion is not part of the supplied command sequence.

Video contains materially more privacy-sensitive information than the requested still image. Storing it at a fixed path under /tmp increases its discoverability and leaves its retention duration undefined. Actual access by another local account depends on the resulting file permissions and operating-system controls, but other processes operating under the same account can access the artifact while it remains present.

Attack Path

  1. A user requests a still photograph.
  2. The skill activates the selected webcam and records five seconds to a predictable MP4 path.
  3. A single frame is extracted into a JPEG.
  4. The command completes without deleting the MP4 recording.
  5. Another process with sufficient local permissions reads or copies the retained video before it is manually removed or replaced.

...[truncated 469 chars]

Remediation
View remediation

Remediation Suggestions

  • Delete each warm-up video immediately after successful frame extraction.
  • Use an exit trap so cleanup also occurs after command failure, interruption, or partial execution.
  • Store intermediate footage in an invocation-specific directory with mode 0700 and files protected by umask 077.
  • Clearly disclose that producing the photograph temporarily requires a five-second video capture.
  • Minimize the recording duration where camera exposure behavior permits.
  • Consider capturing frames directly in memory or through a pipeline that avoids persistent intermediate video.
  • Retain an intermediate recording only when the user explicitly requests video retention and selects an approved destination.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill performs webcam recording and image extraction, saving outputs to local files, but does not include any privacy warning, consent requirement, or visible notice that camera capture is about to occur. In a camera-access context, the absence of explicit user-warning and confirmation makes the skill significantly more dangerous because it could collect sensitive images of a person or surroundings without sufficiently informed consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description uses broad, everyday phrases like 'take a photo,' 'snapshot,' or 'see them,' which can match ordinary conversational requests and increase the chance of unintended invocation. Because the action activates a webcam and captures an image, accidental triggering creates a meaningful privacy risk even if the author likely intended convenience rather than abuse.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.