Back to skill

Security audit

Full AI pipeline to create dark motivational TikTok/Reels videos using REAL video footage. Generates script (Claude), voiceover (ElevenLabs), searches real dark/cinematic video clips from Pexels API (no AI image generation), adds animated text overlays (MoviePy), color grading (FFmpeg), and exports final 1080x1920 MP4. Use this skill for: motivation video, dark

Security checks for vulnerabilities and agentic risk

Overview

The skill largely does what it says, but it needs Review because it downloads and processes remote media without strong bounds and uses unpinned third-party installs.

Install only in an isolated environment with limited filesystem access, use API keys scoped to these services, pin dependencies before use, and avoid running it on sensitive machines until media downloads are bounded by host, content type, redirect, and size checks.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
pipeline_full.py:186
Finding

Unvalidated and Unbounded Download of Remotely Supplied Media

Content
View full analysis
= 720 and "mp4" in f.get("file_type", "")), files[0]["link"] if files else None ) if not url: continue clip_path = os.path.join(output_dir, f"clip_{len(collected):02d}.mp4") print(f" Downloading {len(collected)+1}/{needed}: {video.get('duration','?')}s by {video.get('user',{}).get('name','?')}") # Stream download dl = requests.get(url, stream=True, timeout=90) dl.raise_for_status() with open(clip_path, "wb") as f: for chunk in dl.iter_content(chunk_size=8192): f.write(chunk) ``` The documented implementation in `SKILL.md` contains the same behavior: ```python path = os.path.join(output_dir, f"clip_{len(collected):02d}.mp4") with open(path, "wb") as f: for chunk in requests.get(url, stream=True, timeout=60).iter_content(8192): f.write(chunk) ``` ### Technical Analysis The download URL is taken directly from the Pexels API response and passed to `requests.get()` without validating its scheme, destination hostname, redirects, declared content type, or expected file size. Python Requests follows redirects by default. The downloaded content is stored with an `.mp4` extension regardless of its actual type and is subsequently opened by MoviePy and FFmpeg. Consequently, the code crosses two trust boundaries: it permits a remote response to select a network destination, and then supplies untrusted bytes to complex native media parsers. The initial Pexels API request is necessary for the declared stock-footage functionality. However, unrestricted destination selection and unbounded downloads exceed the minimum network a ...[truncated 1471 chars]
Remediation
View remediation
MAX_CLIP_BYTES: raise ValueError("Media exceeds maximum permitted size") f.write(chunk) ``` ]]>

T08 · Insecure Dependencies

Warning
Location
pipeline_full.py:9
Finding

Unpinned Third-Party Runtime Dependencies

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (21)

Tainted flow: 'ANTHROPIC_KEY' from os.getenv (line 27, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · pipeline_full.py (reported line 105)May include surrounding context.

python
def generate_script(topic, tone, duration):
    print(f"  Topic: {topic} | Tone: {tone} | {duration}s")
    r = requests.post(
        "https://api.anthropic.com/v1/messages",
        headers={
            "x-api-key": ANTHROPIC_KEY,

Tainted flow: 'ELEVENLABS_KEY' from os.getenv (line 28, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · pipeline_full.py (reported line 134)May include surrounding context.

python
if line["text"] == "[PAUSE]":
            segments.append(AudioSegment.silent(duration=line["duration_ms"]))
            continue
        r = requests.post(
            f"https://api.elevenlabs.io/v1/text-to-speech/{voice_id}",
            headers={"xi-api-key": ELEVENLABS_KEY, "Content-Type": "application/json"},
            json={

Tainted flow: 'PEXELS_KEY' from os.getenv (line 29, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · pipeline_full.py (reported line 171)May include surrounding context.

python
break
        print(f"  Pexels search: '{query}'")
        try:
            r = requests.get(
                "https://api.pexels.com/videos/search",
                headers={"Authorization": PEXELS_KEY},
                params={

Unvalidated Output Injection

High
Category
Output Handling
Confidence
85% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · SKILL.md (reported line 290)May include surrounding context.

md
print("[3/5] Pexels..."); clips = fetch_video_clips(visual_theme, duration, pk, script=script)
    print("[4/5] Compose..."); raw = compose_video(clips, audio, script, "raw.mp4", bg_music_path)
    print("[5/5] Grade...")
    subprocess.run([
        "ffmpeg","-y","-i",raw,"-vf",
        "curves=blue='0/0.05 1/1.1',eq=contrast=1.15:brightness=-0.04:saturation=0.60,vignette=PI/4",
        "-c:v","libx264","-crf","17","-c:a","copy", output

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 311)May include surrounding context.

md
brew install ffmpeg  (or apt install ffmpeg)
  Font: fonts/BebasNeue-Regular.ttf  (from fonts.google.com)

API Keys (set in .env or environment):
  ANTHROPIC_API_KEY
  ELEVENLABS_API_KEY
  PEXELS_API_KEY  (free at https://www.pexels.com/api/)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · pipeline_full.py (reported line 13)May include surrounding context.

python
brew install ffmpeg  (or apt install ffmpeg)
  Font: fonts/BebasNeue-Regular.ttf  (from fonts.google.com)

API Keys (set in .env or environment):
  ANTHROPIC_API_KEY
  ELEVENLABS_API_KEY
  PEXELS_API_KEY  (free at https://www.pexels.com/api/)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill performs network access, reads environment variables, writes files, and invokes FFmpeg via subprocess, but the manifest does not declare any explicit tool scope or permissions. This weakens reviewability and containment because a caller cannot easily determine the skill's operational capabilities before execution.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
import json, requests

def generate_script(topic, tone, duration, api_key):
    r = requests.post(
        "https://api.anthropic.com/v1/messages",
        headers={"x-api-key": api_key, "anthropic-version": "2023-06-01", "content-type": "application/json"},
        json={

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

md
if line["text"] == "[PAUSE]":
            segs.append(AudioSegment.silent(duration=line["duration_ms"]))
            continue
        r = requests.post(
            f"https://api.elevenlabs.io/v1/text-to-speech/{voice_id}",
            headers={"xi-api-key": api_key, "Content-Type": "application/json"},
            json={"text": line["text"], "model_id": "eleven_multilingual_v2",

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The prompt instructions and required JSON fields are written to produce English motivational content, and the CLI exposes no option for user language or locale preference. This can violate language/locale policy when a skill forces a specific language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
def generate_script(topic, tone, duration):
    print(f"  Topic: {topic} | Tone: {tone} | {duration}s")
    r = requests.post(
        "https://api.anthropic.com/v1/messages",
        headers={
            "x-api-key": ANTHROPIC_KEY,

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · pipeline_full.py (reported line 105)May include surrounding context.

python
def generate_script(topic, tone, duration):
    print(f"  Topic: {topic} | Tone: {tone} | {duration}s")
    r = requests.post(
        "https://api.anthropic.com/v1/messages",
        headers={
            "x-api-key": ANTHROPIC_KEY,

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · pipeline_full.py (reported line 105)May include surrounding context.

python
def generate_script(topic, tone, duration):
    print(f"  Topic: {topic} | Tone: {tone} | {duration}s")
    r = requests.post(
        "https://api.anthropic.com/v1/messages",
        headers={
            "x-api-key": ANTHROPIC_KEY,

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
def generate_script(topic, tone, duration):
    print(f"  Topic: {topic} | Tone: {tone} | {duration}s")
    r = requests.post(
        "https://api.anthropic.com/v1/messages",
        headers={
            "x-api-key": ANTHROPIC_KEY,
            "anthropic-version": "2023-06-01",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · pipeline_full.py (reported line 106)May include surrounding context.

python
def generate_script(topic, tone, duration):
    print(f"  Topic: {topic} | Tone: {tone} | {duration}s")
    r = requests.post(
        "https://api.anthropic.com/v1/messages",
        headers={
            "x-api-key": ANTHROPIC_KEY,
            "anthropic-version": "2023-06-01",

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · pipeline_full.py (reported line 134)May include surrounding context.

python
if line["text"] == "[PAUSE]":
            segments.append(AudioSegment.silent(duration=line["duration_ms"]))
            continue
        r = requests.post(
            f"https://api.elevenlabs.io/v1/text-to-speech/{voice_id}",
            headers={"xi-api-key": ELEVENLABS_KEY, "Content-Type": "application/json"},
            json={

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
segments.append(AudioSegment.silent(duration=line["duration_ms"]))
            continue
        r = requests.post(
            f"https://api.elevenlabs.io/v1/text-to-speech/{voice_id}",
            headers={"xi-api-key": ELEVENLABS_KEY, "Content-Type": "application/json"},
            json={
                "text": line["text"],

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · pipeline_full.py (reported line 135)May include surrounding context.

python
segments.append(AudioSegment.silent(duration=line["duration_ms"]))
            continue
        r = requests.post(
            f"https://api.elevenlabs.io/v1/text-to-speech/{voice_id}",
            headers={"xi-api-key": ELEVENLABS_KEY, "Content-Type": "application/json"},
            json={
                "text": line["text"],

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 150)May include surrounding context.

md
print(f"  Pexels search: '{query}'")
        try:
            r = requests.get(
                "https://api.pexels.com/videos/search",
                headers={"Authorization": PEXELS_KEY},
                params={
                    "query": query,

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · pipeline_full.py (reported line 172)May include surrounding context.

python
print(f"  Pexels search: '{query}'")
        try:
            r = requests.get(
                "https://api.pexels.com/videos/search",
                headers={"Authorization": PEXELS_KEY},
                params={
                    "query": query,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · pipeline_full.py (reported line 318)May include surrounding context.

python
"-c:a", "copy",
        output_path
    ]
    result = subprocess.run(cmd, capture_output=True, text=True)
    if result.returncode != 0:
        print(f"  FFmpeg warning (using ungraded): {result.stderr[-300:]}")
        import shutil; shutil.copy(input_path, output_path)

Static analysis

Detected: suspicious.prompt_injection_instructions

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
SKILL.md:44