Back to skill

Security audit

lowkey viral

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward guide for using the lowkey viral API to create social videos and slideshows, with its external API use and API-key requirement disclosed.

Install only if you intend to use lowkeyviral.com with a paid API key. Be aware that prompts, uploaded images, and generated assets are sent to the service, API calls can consume credits, and deletion of briefs should be confirmed explicitly before running.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest says to use the skill when the user wants to create "social media content, short videos, viral clips, reels, TikToks, carousels, slideshows, or any vertical video for social platforms." Several of these phrases are broad and overlap with common creative requests, and the file does not provide exclusion conditions or narrower trigger constraints.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
env:
        - LOWKEY_VIRAL_API_KEY
      bins:
        - curl
    primaryEnv: LOWKEY_VIRAL_API_KEY
    homepage: https://github.com/tiotdev/lowkey-viral
    emoji: "🎬"

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill documents a DELETE endpoint for briefs without an explicit warning that the action is destructive and may permanently remove user content. In an agent setting, omission of such guardrails can increase the chance of accidental deletion when the agent follows instructions too aggressively.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.