Back to skill

Security audit

Video Cut

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed video rough-cut workflow that uses expected media-processing tools and does not show hidden persistence, credential handling, or exfiltration behavior.

Before installing, confirm you trust the separate /video-understand prerequisite and run the skill in a dedicated project folder. Expect it to download or process videos you provide, create work/ intermediates, and write rendered video/report files; do not provide account cookies or private media unless you are comfortable with those local tools processing them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is for a comprehensive video-editing pipeline that shortens raw long-form videos into a first-cut output. The supplied code does not implement that workflow. Instead, it is a narrowly scoped verification script: it writes sample JSON inputs, runs another script (build_edit.py), reads the JSON output, and checks that source_duration_s exactly matches an expected floating-point value. This is a testing/QA utility related to edit-plan protocol precision, not the advertised end-to-end editing skill. While it may support the broader project, its primary behavior is materially different from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description promises an end-to-end automatic first-cut editing skill for long-form video. The provided code chunk, however, is a unit test file focused on two helper scripts: one that inspects keep/drop bounds against transcript words and one that assigns playback speeds to kept segments based on word density, with constraints like deadband edges and adjacent speed smoothing. This is at most a small supporting component of a larger editing system, not the described end-to-end skill. Because the actual code shown has a materially narrower and different purpose than the declared functionality, this is a mismatch.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · scripts/inspect_bounds.py (reported line 47)May include surrounding context.

python
return f"WARNING: dangling exit: ends on '{last.strip()}' (hanging word)"
    # capitalized X Y proper-noun split: keep "Southern", drop "Cross". A trailing
    # ./!/?/… means the kept word ENDS a sentence (a clean boundary, and the next
    # capital just starts the next sentence) — don't warn on those.
    if (nxt and is_cap(last) and is_cap(nxt) and norm(last) not in ("i",)
            and not last.strip().endswith((".", "!", "?", "…"))):
        return f"WARNING: dangling exit: splits proper noun '{last.strip()} {nxt.strip()}'"

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · tests/test_inspect_bounds.py (reported line 34)May include surrounding context.

python
transcript_path = root / "transcript.json"
            plan_path.write_text(json.dumps(plan), encoding="utf-8")
            transcript_path.write_text(json.dumps(transcript), encoding="utf-8")
            env = os.environ.copy()
            env["PYTHONIOENCODING"] = encoding
            return subprocess.run(
                [sys.executable, str(SCRIPT), str(plan_path), str(transcript_path)],

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill instructs the agent to use shell, environment inspection, file reads/writes, network download tooling, and media-processing commands, but it does not declare any explicit tool scope such as allowed-tools or permissions. That makes the effective capability boundary ambiguous and can lead to over-privileged execution in hosts that rely on manifest-level scoping, especially because the workflow includes external downloads and arbitrary local media handling.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/check_project_protocol.py (reported line 58)May include surrounding context.

python
write_json(coarse_path, coarse)
        write_json(transcript_path, transcript)

        subprocess.run(
            [
                sys.executable,
                str(SCRIPT_DIR / "build_edit.py"),

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/cut_render.py (reported line 96)May include surrounding context.

python
out,
    ]
    print(f"[render] launching ffmpeg with {n} seeked inputs + concat (single re-encode)...")
    r = subprocess.run(cmd)
    if r.returncode != 0:
        print("[render] FFMPEG FAILED", r.returncode); sys.exit(1)
    print(f"[render] DONE -> {out}")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/selfcheck_frames.py (reported line 49)May include surrounding context.

python
strip = os.path.join(out_dir, "joins_strip.png")
    cmd = ["ffmpeg", "-y", "-loglevel", "error", "-i", mp4, "-vf", vf,
           "-frames:v", "1", "-vsync", "0", strip]
    subprocess.run(cmd)
    print(f"[selfcheck] wrote {strip} (rows=joins, cols=[-0.12s, join, +0.12s])")

    # blackdetect on the output

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/selfcheck_frames.py (reported line 54)May include surrounding context.

python
# blackdetect on the output
    print("[selfcheck] blackdetect on output:")
    r = subprocess.run(["ffmpeg", "-i", mp4, "-vf", "blackdetect=d=0.1:pic_th=0.98",
                        "-an", "-f", "null", "-"], capture_output=True, text=True)
    blk = [ln for ln in r.stderr.splitlines() if "blackdetect" in ln.lower()]
    if blk:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · tests/test_inspect_bounds.py (reported line 36)May include surrounding context.

python
transcript_path.write_text(json.dumps(transcript), encoding="utf-8")
            env = os.environ.copy()
            env["PYTHONIOENCODING"] = encoding
            return subprocess.run(
                [sys.executable, str(SCRIPT), str(plan_path), str(transcript_path)],
                capture_output=True,
                env=env,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · tests/test_inspect_bounds.py (reported line 92)May include surrounding context.

python
json.dumps({"language": "en", "segments": [{"words": words}]}),
                encoding="utf-8",
            )
            result = subprocess.run(
                [
                    sys.executable,
                    str(ASSIGN_SPEED_SCRIPT),

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/transcribe.py:12