Back to skill

Security audit

Reelyze - Instagram Reel, TikTok & Shorts Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Reelyze API integration, but users should only submit public video URLs and keep credentials pointed at the official Reelyze API endpoint.

Install only if you trust Reelyze with the public video URLs, topics, and generated requests you submit. Store the API key securely, do not paste it into shared chats or logs, and leave REELYZE_BASE_URL at https://api.getreelyze.com unless you intentionally use a trusted Reelyze-controlled endpoint.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:21
Finding

Configurable API Origin Can Exfiltrate the Bearer API Key

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 21–23, 97–104, 136–143, and 158–171
Vulnerability Type: Unrestricted credential destination
Risk Level: Medium

Vulnerable Code

yaml
- name: REELYZE_BASE_URL
  required: false
  description: API base URL. Defaults to https://api.getreelyze.com.

The configurable origin is subsequently used in authenticated requests:

bash
curl -s -X POST "$REELYZE_BASE_URL/v1/analyze" \
  -H "Authorization: Bearer $REELYZE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://www.instagram.com/reel/XXXX/"}'

The same pattern is used for job polling and content-generation endpoints:

bash
curl -s "$REELYZE_BASE_URL/v1/jobs/abc..." \
  -H "Authorization: Bearer $REELYZE_API_KEY"
bash
curl -s -X POST "$REELYZE_BASE_URL/v1/script" \
  -H "Authorization: Bearer $REELYZE_API_KEY" -H "Content-Type: application/json" \
  -d '{"topic":"how I edit reels in 10 minutes","duration_seconds":30,"language":"English"}'

Technical Analysis

The Skill allows REELYZE_BASE_URL to be supplied through the environment without requiring HTTPS or validating the destination hostname. It then attaches the sensitive REELYZE_API_KEY as an HTTP bearer credential to requests made to that configurable origin.

This creates a credential-confusion vulnerability: the authentication token intended for api.getreelyze.com is sent to whichever server is named by REELYZE_BASE_URL. The Skill provides no origin allowlist, hostname verification policy, or user confirmation before sending the credential to a non-default destination.

The issue is exploitable when an attacker can influence the Agent's environment, deployment configuration, wrapper script, or other mechanism that sets REELYZE_BASE_URL. It does not require arbitrary code execution inside the Skill.

Attack Path

  1. The victim configures a valid REELYZE_API_KEY for the Agent.
  2. An attacker or compromised deployment co ...[truncated 1185 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin authenticated requests to the documented production origin:

    text
    https://api.getreelyze.com
    
  2. If custom endpoints are operationally necessary, enforce an explicit allowlist of trusted HTTPS origins before attaching the Authorization header.

  3. Reject base URLs that:

    • Use plaintext HTTP.
    • Contain embedded user information.
    • Resolve to unapproved hostnames.
    • Use unexpected ports.
    • contain paths, queries, or fragments where only an origin is expected.
  4. Normalize and compare the URL scheme, hostname, and port rather than relying on string-prefix checks.

  5. Do not forward the Authorization header if a request is redirected to a different origin.

  6. Require explicit user confirmation before sending a credential to any non-default development or staging endpoint.

  7. Document that REELYZE_BASE_URL is security-sensitive and must not be controlled by untrusted users or inherited from untrusted environment configuration.

  8. Rotate any API key that may previously have been used with an untrusted base URL, and review account usage for unauthorized quota consumption.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directs the agent to send user-provided video URLs to Reelyze's external API but does not warn the user that their supplied URL and related metadata will be transmitted to a third party. This creates a privacy and consent issue, especially if users provide sensitive, private, or identifying links under the assumption processing is local.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The skill explicitly performs external transmission of user-supplied video URLs and an Authorization bearer token to a third-party API. In context this is expected functionality, but it is still security-relevant because it exposes user data and credentials to an external service and therefore requires clear consent and trust boundaries.

Content

Scanner excerpt · SKILL.md (reported line 134)May include surrounding context.

Full worked example: analyze a reel

bash
# 1) Submit the analysis
curl -s -X POST "$REELYZE_BASE_URL/v1/analyze" \
  -H "Authorization: Bearer $REELYZE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://www.instagram.com/reel/XXXX/"}'

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The endpoint examples and request bodies hard-code language as English, which can steer agents to use English by default for generated scripts and ideas. The file does not clearly state that language should follow user preference or that other languages are supported via opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.