Back to skill

Security audit

Cutrix Video Translate

Security checks for vulnerabilities and agentic risk

Overview

This skill is a mostly coherent guide for using the Cutrix video translation SDK, with some packaging and supply-chain cautions users should review.

Install only if you are comfortable sending selected videos, audio, subtitles, and task metadata to Cutrix for cloud processing. Keep API keys and ClawHub tokens out of code, logs, and shared transcripts, and consider pinning and hash-locking the SDK version in controlled environments.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Mutable and Unverified Third-Party SDK Dependency

Content
View full analysis
=0.0.2,<1.0.0 ``` The dependency is subsequently installed and imported through the documented workflow: ```bash pip install -r requirements.txt python scripts/check_install.py ``` ### Technical Analysis The requirement is described as a reproducibility pin, but `>=0.0.2,<1.0.0` permits package managers to install any compatible future release below version 1.0.0. It is therefore a mutable version range rather than an exact pin. The source code of `cutrix-video-translate-sdk` is not included in the audited project. Consequently, the behavior of the installed package—including its installation process, module initialization, network activity, and access to environment variables—cannot be verified from this artifact. No package hashes are provided to authenticate the selected distribution artifact. After installation, `scripts/check_install.py` executes `import cutrix`. Python imports execute package-level initialization code, so a compromised or malicious package release satisfying the version range could run code in the current process. This finding does not establish that the current SDK release is malicious; it identifies the absence of controls preventing a future or substituted compatible release from being installed and executed. ### Attack Path 1. An attacker compromises the upstream publisher account, package distribution infrastructure, or a future release of `cutrix-video-translate-sdk`. 2. The attacker publishes a malicious version that satisfies `>=0.0.2,<1.0.0`. 3. A user or agent runs `pip install -r requirements.txt`. 4. The package resolver selects and installs the malicious compatible version. 5. Inst ...[truncated 1010 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The README identifies the skill as a 'Cutrix Python SDK' / 'cutrix-python-sdk' publishing artifact, while the manifest metadata describes a different skill: 'cutrix-video-translate'. This identity mismatch can mislead users and agents about what is being installed or published, increasing supply-chain and trust-confusion risk, especially in agent skill registries where metadata drives automated selection and invocation.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
inside a domestic assistant (e.g. WorkBuddy / “小龙虾” ecosystems) that supports `SKILL.md`-based skill packs—this directory can be the skill root as-is

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

md
inside a domestic assistant (e.g. WorkBuddy / “小龙虾” ecosystems) that supports `SKILL.md`-based skill packs—this directory can be the skill root as-is

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 359)May include surrounding context.

md
inside a domestic assistant (e.g. WorkBuddy / “小龙虾” ecosystems) that supports `SKILL.md`-based skill packs—this directory can be the skill root as-is

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 367)May include surrounding context.

md
inside a domestic assistant (e.g. WorkBuddy / “小龙虾” ecosystems) that supports `SKILL.md`-based skill packs—this directory can be the skill root as-is

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README says the folder is only a ClawHub-compatible skill for the official SDK and 'not a second implementation of the API,' but it simultaneously presents itself as a different SDK skill altogether. This contradictory framing can obscure the true scope of the artifact and make reviewers or automated systems trust the wrong code or package lineage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README instructs users to authenticate with a bearer-style token (clh_...) but provides no warning to treat the token as a secret, avoid committing it to files, shell history, logs, screenshots, or prompt transcripts. In an agent-oriented workflow, omission of secret-handling guidance is more dangerous because agents may echo commands, store session context, or write setup scripts that inadvertently expose credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs users to submit local video files through an SDK that performs cloud upload and remote processing, but it does not clearly warn that the full video content and associated metadata will leave the local environment and be sent to Cutrix infrastructure. This can mislead users into exposing sensitive audio, faces, subtitles, or embedded business data when they believe they are only invoking a local SDK function.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file presents major instructions in Chinese and English together, and several operational sections are primarily Chinese. Because the skill does not state a language preference, offer alternatives, or justify a locale-specific audience, this can be interpreted as imposing a language/locale assumption without explicit user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.