Back to skill

Security audit

Auto Subtitle

Security checks for vulnerabilities and agentic risk

Overview

This subtitle tool is broadly purpose-aligned, but it needs review because its file restore and output handling can overwrite user-writable files in unsafe directories.

Install only if you trust the directories you will process and are comfortable sending extracted audio to OpenAI for transcription. Avoid running --undo or processing videos in shared or attacker-writable folders until the undo log and output/temp file handling are hardened, and prefer pinned dependencies in an isolated environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
install.sh:22
Finding

Unpinned Third-Party Dependencies Create Supply-Chain Exposure

Content
View full analysis
=1.0.0", "pydub": ">=0.25.0" } ``` ### Technical Analysis The installer resolves mutable package versions from the active pip package index without exact version pins, integrity hashes, a lock file, or an explicitly trusted index. Consequently, the code installed and subsequently executed can differ from the code that was reviewed. The `pydub` package is installed but is not imported or otherwise used by `source/auto_subtitle.py`, unnecessarily increasing the project's supply-chain attack surface. Broad lower-bound constraints in `skill.json` do not prevent installation of a future compromised or incompatible release. Depending on the resolved distribution, hostile code could execute through Python build hooks during installation or when the installed package is imported and used. ### Attack Path 1. An attacker compromises a permitted dependency release, its publisher account, or a package index selected through the user's pip configuration. 2. The attacker publishes a version satisfying `openai>=1.0.0` or `pydub>=0.25.0`. 3. A user or agent runs `install.sh`. 4. `pip install openai pydub` resolves and installs the attacker-controlled release because no exact version or hash is required. 5. Malicious code executes during package building, installation, import, or runtime use with the privileges of the user running the installer. ### Impact Assessment Successful exploitation could provide arbitrary code execution with the privileges of the installing or executing account. This may expo ...[truncated 252 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
source/auto_subtitle.py:155
Finding

Untrusted Undo Log Allows Attacker-Directed File Overwrite

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
source/auto_subtitle.py:54
Finding

Predictable Temporary and Output Paths Permit Symlink-Based File Overwrite

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The documented purpose does not accurately describe important real behavior: local media is sent to an external OpenAI transcription service, and the claimed 'video frame extraction' functionality appears unsupported by the implementation. This kind of description-behavior mismatch is dangerous because users may expose sensitive media content or API credentials without realizing the skill performs network-dependent processing beyond what the description makes clear.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares no explicit tool scope or permissions even though its documented behavior implies access to environment variables, filesystem read/write, and shell-adjacent capabilities such as ffmpeg invocation. Missing scope declarations increase the chance of over-broad execution in an agent environment and prevent users from making an informed trust decision about what the skill can access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill does not clearly warn that audio from local video files is transmitted to the OpenAI Whisper API for processing. In a subtitle-generation context, uploaded audio may contain confidential meetings, personal conversations, or proprietary content, so lack of disclosure creates a meaningful privacy and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script presents all user-facing messages and usage guidance in Chinese, including installation status, errors, and examples. Because the file provides no language choice or documented locale justification, it appears to force a specific language for all users.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · install.sh (reported line 19)May include surrounding context.

sh
# 检查 ffmpeg
if ! command -v ffmpeg &> /dev/null; then
    echo "⚠️  警告:未找到 ffmpeg"
    echo "   Ubuntu/Debian: sudo apt install ffmpeg"
    echo "   macOS: brew install ffmpeg"
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · source/auto_subtitle.py (reported line 247)May include surrounding context.

python
# 检查 ffmpeg
if ! command -v ffmpeg &> /dev/null; then
    echo "⚠️  警告:未找到 ffmpeg"
    echo "   Ubuntu/Debian: sudo apt install ffmpeg"
    echo "   macOS: brew install ffmpeg"
fi

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest/docstring claims the skill generates subtitles by combining video frame extraction with speech-to-text. In the implementation, subtitle generation is driven solely by ffmpeg audio extraction and OpenAI transcription, with no code that samples, analyzes, or otherwise uses video frames for subtitle generation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Natural-language strings in the module description and CLI output are fixed to Chinese, which can impose a language/locale constraint on users without opt-in. The file does not indicate that the tool is intentionally region-specific or provide an alternative language option.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · source/auto_subtitle.py (reported line 29)May include surrounding context.

python
def check_ffmpeg():
    """检查 ffmpeg 是否可用"""
    try:
        subprocess.run(["ffmpeg", "-version"], capture_output=True, check=True)
        return True
    except (subprocess.CalledProcessError, FileNotFoundError):
        return False

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · source/auto_subtitle.py (reported line 65)May include surrounding context.

python
]
    
    try:
        subprocess.run(cmd, capture_output=True, check=True)
        return audio_path
    except subprocess.CalledProcessError as e:
        print(f"    ❌ 音频提取失败:{e}")

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script reads an API key from the environment and uploads extracted audio from local videos to OpenAI, but the stated purpose does not clearly disclose this external transmission. In a local media-processing tool, undisclosed network exfiltration of user content is security-relevant because videos may contain sensitive speech or regulated data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Local audio is transmitted to a remote Whisper API without an explicit user-facing warning at execution time. This creates a privacy and data-handling risk because users may assume the tool operates entirely locally while it actually exports potentially sensitive speech content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest description is written entirely in Chinese, and the file provides no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy for natural-language constraints, this can be a locale/language restriction without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.