Back to skill

Security audit

mp4-to-mp3-extractor

Security checks for vulnerabilities and agentic risk

Overview

This is a real MP4-to-MP3 skill, but it automatically changes Python environments and downloads executable dependencies in ways users should review before installing.

Review this skill before installing. It can read a chosen video folder and write MP3 outputs, which matches its purpose, but it also changes Python package state, uses a shared virtual environment, and may download and run FFmpeg automatically. Prefer a version that requires preinstalled, trusted FFmpeg and pinned dependencies in a private venv, and avoid running the documented sudo symlink workaround unless you fully understand the system-wide effect.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T08 · Insecure Dependencies

Error
Location
scripts/extract.py:25
Finding

Automatic Installation of Unpinned Third-Party Dependencies

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/ensure_package.py:27
Finding

Import-Time Forced Replacement of Foundational Host Python Packages

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/extract.py:38
Finding

Unverified Remote FFmpeg Binary Download and Execution

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/config.py:27
Finding

Virtual Environment Shared Outside the Skill Security Boundary

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (49)

Chaining Abuse

High
Category
Tool Misuse
Confidence
87% confidence
Finding

The chained command sudo apt update && sudo apt install python3-venv combines multiple privileged operations into a single copy-paste step. In agent-oriented environments, chained privileged commands reduce review opportunities and make it easier for unsafe or unintended actions to be executed wholesale.

Content

Scanner excerpt · README.md (reported line 31)May include surrounding context.

md
**修复步骤 (Linux示例):**

\# 1\. 安装 venv 支持  
sudo apt update && sudo apt install python3-venv  
\# 2\. 建立软链接 (路径请根据实际 Python 安装位置修改)  
sudo ln \-s /usr/bin/python3 /usr/bin/python  
\# 3\. 重启服务

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the actual implementation does not perform media extraction at all and instead focuses on unrelated logging or path management, the skill is materially deceptive about what it does. Even if not overtly malicious, such mismatch undermines trust and can conceal unwanted file operations or create a pathway for future abuse under an innocuous label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the actual implementation does not perform media extraction at all and instead focuses on unrelated logging or path management, the skill is materially deceptive about what it does. Even if not overtly malicious, such mismatch undermines trust and can conceal unwanted file operations or create a pathway for future abuse under an innocuous label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the actual implementation does not perform media extraction at all and instead focuses on unrelated logging or path management, the skill is materially deceptive about what it does. Even if not overtly malicious, such mismatch undermines trust and can conceal unwanted file operations or create a pathway for future abuse under an innocuous label.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file implements a broad package-installation utility that can manage arbitrary dependencies and sources, which materially exceeds the needs of batch MP4-to-MP3 conversion. Scope expansion is dangerous because it introduces code-fetching and environment-modifying capabilities unrelated to the advertised function, a common sign of unnecessary attack surface or covert functionality.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The module mutates the Python packaging environment immediately on import by reinstalling packaging, setuptools, and wheel. Import-time side effects are dangerous because simply loading the module triggers system modifications without informed action from the user, and they affect all consumers of the module, not just an explicit setup flow.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code explicitly supports installation from remote git/HTTP sources and local archives, which can fetch and execute untrusted third-party code. This is a severe supply-chain risk and effectively gives the skill a code-download-and-run capability unrelated to MP4-to-MP3 extraction, making the context substantially more dangerous.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/env_manager.py (reported line 222)May include surrounding context.

python
sys.exit(1)

    # 传递环境变量防止递归
    env = os.environ.copy()
    env["RUNNING_IN_VENV"] = "true"

    logger.info(f"   当前Python: {sys.executable}")

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The subprocess-driven FFmpeg installation acquires and executes external code beyond the core purpose of converting files. Because it is automatic and non-interactive, a user invoking a media tool may unknowingly trigger binary download and install behavior that could be abused through supply-chain compromise or unexpected environment modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file describes behavior that recursively scans directories, preserves folder structure, writes extracted MP3 files, and stores logs, but it does not include a clear user-facing warning that the skill will create output files and retain execution logs. For markdown files, missing disclosures about actions affecting user data or system state should be flagged when warnings are omitted.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
91% confidence
Finding

The README instructs users to run sudo apt update && sudo apt install python3-venv, which normalizes elevated execution for setup. While common for package installation, encouraging root-level commands in skill docs increases risk because users may execute them without understanding system-wide effects, especially in an agent-tooling context.

Content

Scanner excerpt · README.md (reported line 31)May include surrounding context.

md
**修复步骤 (Linux示例):**

\# 1\. 安装 venv 支持  
sudo apt update && sudo apt install python3-venv  
\# 2\. 建立软链接 (路径请根据实际 Python 安装位置修改)  
sudo ln \-s /usr/bin/python3 /usr/bin/python  
\# 3\. 重启服务

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
95% confidence
Finding

The README instructs users to create a system-wide symlink with sudo ln -s /usr/bin/python3 /usr/bin/python. Modifying /usr/bin as root can interfere with system tooling, break distributions that intentionally omit python, and conditions users to make privileged persistent changes for a single skill.

Content

Scanner excerpt · README.md (reported line 33)May include surrounding context.

md
\# 1\. 安装 venv 支持  
sudo apt update && sudo apt install python3-venv  
\# 2\. 建立软链接 (路径请根据实际 Python 安装位置修改)  
sudo ln \-s /usr/bin/python3 /usr/bin/python  
\# 3\. 重启服务  
systemctl \--user restart openclaw-gateway

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README says users can directly tell the agent phrases like '帮我把…都转成mp3' and '批量把…这些视频转音频…' without defining explicit trigger boundaries, exclusions, or a constrained command format. In a markdown skill description, such broad natural-language activation examples can overlap with ordinary conversation and make invocation scope unclear.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README suggests a workflow that includes downloading a remote Douyin video even though the skill is presented as a local MP4-to-MP3 extractor and no documented capability here supports safe downloading. This can mislead an agent or user into chaining unrelated tools or unsafe actions against remote content beyond the skill's stated scope.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares executable behavior that invokes Python via shell but does not define any explicit tool scope or permission boundary. This is dangerous because an agent may execute shell-capable actions without clear least-privilege constraints, increasing the chance of unintended command execution or broader filesystem/process access than users expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Overly broad trigger phrases can cause the skill to activate on loosely related everyday requests, including cases where the user did not intend file conversion or shell execution. In a skill that can write files and invoke Python, over-triggering increases the risk of unintended actions and user confusion.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The invocation guidance appears broad enough to capture loosely related requests, including workflows like downloading videos before processing. This expands the operational scope beyond straightforward local conversion and can lead to unintended network or filesystem activity if the agent invokes the skill too aggressively.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The mismatch between the file header branding and the actual behavior obscures the true capability of the module. Mislabeling a package installer as part of an MP4-to-MP3 extractor reduces transparency and can prevent reviewers or users from understanding that the code changes the environment and fetches packages.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
96% confidence
Finding

This subprocess call invokes pip to force-install a package into the current Python environment. Because it runs as part of an import-time repair routine, it performs privileged system mutation without user consent and can unexpectedly alter dependency state for any workflow that imports this module. In the context of an MP4-to-MP3 skill, modifying packaging internals is unjustified and expands the attack surface.

Content

Scanner excerpt · scripts/ensure_package.py (reported line 30)May include surrounding context.

python
"""专门为老项目(使用 pkg_resources 的 setup.py)修复 setuptools 版本"""
    try:
        # 先强制修复损坏的 packaging 包(关键!解决无RECORD文件报错)
        subprocess.check_call([
            sys.executable, "-m", "pip", "install",
            "--verbose", "--ignore-installed", "--no-deps", "packaging==26.1"
        ])

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
97% confidence
Finding

This call force-reinstalls setuptools and wheel, directly mutating core packaging tools in the active environment. Reinstalling foundational build tooling at import time can break unrelated software, downgrade security posture, or facilitate later installation of untrusted packages. For a media conversion skill, this capability is unnecessary and therefore more suspicious and dangerous.

Content

Scanner excerpt · scripts/ensure_package.py (reported line 35)May include surrounding context.

python
"--verbose", "--ignore-installed", "--no-deps", "packaging==26.1"
        ])
        # 再安装兼容的 setuptools + wheel
        subprocess.check_call([
            sys.executable, "-m", "pip", "install",
            "--verbose", "--force-reinstall", "setuptools<=81.2.0", "wheel"
        ])

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

At line 43 the module causes package installation side effects merely by being imported, with no explicit user-facing disclosure or consent flow. Hidden system-modifying behavior increases the risk of unexpected environment compromise and makes auditing and safe use much harder.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/ensure_package.py (reported line 85)May include surrounding context.

python
# 第一步:尝试 import 检查(最快)
    try:
        parts = import_name.split('.')
        mod = __import__(parts[0])
        for part in parts[1:]:
            mod = getattr(mod, part)
        if sub_import:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The automatic pip execution in this range performs system modification and code installation without a clear user disclosure mechanism. Even if intended for convenience, silent dependency changes and remote code retrieval are dangerous in a user-facing skill and inappropriate for a narrow media-conversion task.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.