Back to skill

Security audit

视频剪辑规划

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed video-cutting helper that validates a clip plan, runs ffmpeg/ffprobe on chosen media, and writes expected edited-video and QC artifacts.

Install only if you expect a Chinese-language video-cutting skill that runs local ffmpeg/ffprobe on media you provide. Use a dedicated work directory, keep ffmpeg current, avoid untrusted or malformed media when possible, and be aware that environment variables can affect snapping/render behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是创作流程中的“剪辑环节”工具,核心能力应是根据 clip plan 对视频素材进行裁剪和拼接,并生成剪辑后的视频文件。但实际代码仅是一个辅助性的 QC 函数:读取内存中的 plan 结构,计算 total_duration 与 target_duration 的比值,标记 under/over/ok,必要时添加 warning 或 blocking 条目,并更新 qc 字段。这属于元数据校验/质检逻辑,而不是视频编辑行为。虽然这种 QC 可能是剪辑流程的支持细节,但当前提供的代码片段本身与声明的主要用途存在明显偏离,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是两阶段创作流程中的“剪辑环节”,核心能力应是依据剪辑计划对一个或多个视频源进行裁切拼接并生成 edited_source.mp4。实际代码文件 narrative_selection.py 的功能则是对“required_evidence”结构做验证:检查节点格式、源路径、时间区间、是否在 validated_plan 中以连续片段出现、以及 before 依赖顺序是否满足;同时对音频节点调用 source_audio 检查源是否具有音频流。它不读取 clip_plan.json,不执行视频裁剪/拼接,不写出视频文件,也没有体现声明中的主要产物 edited_source.mp4。因此代码的主要目的与声明明显不一致,属于实质性描述-行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是创作流程中的“剪辑环节”,核心功能应是读取剪辑计划与源视频并产出剪好的视频文件。但代码文件 shot_review.py 的实现完全围绕“审查已渲染视频”展开:使用 ffprobe/ffmpeg 获取逐帧 PTS、检测 scene 变化、汇总短片段和密集切点窗口、与计划时间线做候选关联,并将结果写入 shot_review 报告。文档字符串还明确写着“Read-only internal-shot recall on the actual rendered video; never repair an EDL.”,进一步表明它不是编辑器而是分析器。虽然代码可读取 plan 并检查 sources/meta,但这只是为了验证当前渲染结果与计划绑定关系,不是为了依据计划执行剪辑。因此其主要目的、输入输出语义和产物类型都与声明明显不符,属于实质性描述-行为不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill advertises shell, file read/write, and environment-dependent behavior but does not declare any explicit tool scope or permission boundaries. That makes the runtime trust model ambiguous and can lead to overbroad tool access if the platform defaults to permissive execution, which is a real security concern for a skill that manipulates local files and invokes scripts/ffmpeg-like tooling.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad and can cause the skill to activate in loosely related video-editing contexts without clear exclusions. In a skill that can read/write files and invoke shell-backed processing, overbroad activation increases the risk of unintended execution on sensitive media or the wrong workspace, especially when downstream actions are expensive or destructive.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains all operational instructions in Chinese and does not indicate that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking context. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill emits user-visible status messages in Chinese string literals at L259 and L278-L279. The policy allows locale constraints only when they are opt-in or clearly documented and justified, which is not present in this code file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The function emits a warning message entirely in Chinese, and similar user-visible strings appear elsewhere in the file. This imposes a specific language on users without any opt-in, choice, or documented region-specific justification, which matches the language/locale policy violation criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This log line is user-visible natural language and is hard-coded to Chinese. Because the file does not offer language selection or explain a justified Chinese-only scope, it violates the language/locale policy requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The raised RuntimeError and final status log are natural-language strings presented in Chinese only. Without user opt-in or clear region-specific documentation, these strings force a specific language and therefore constitute a policy violation.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/lib.py (reported line 71)May include surrounding context.

python
str(part) if len(str(part)) <= 240 else str(part)[:237] + "..." for part in cmd
    )
    log(f"运行: {display}")
    return subprocess.run(cmd, capture_output=True, text=True, **kwargs)


# ffmpeg 7 added `-/option path` to read any option's value from a file; ffmpeg 9 removed the

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/lib.py (reported line 91)May include surrounding context.

python
graph = os.path.join(tmp, "probe_filter.txt")
        with open(graph, "w", encoding="utf-8") as fh:
            fh.write("null")
        result = subprocess.run(["ffmpeg", "-hide_banner", "-/filter_complex", graph],
                                stdin=subprocess.DEVNULL, capture_output=True, text=True,
                                timeout=20)
    return "Unrecognized option" not in result.stderr

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The raised RuntimeError messages are hard-coded in Chinese (无法读取视频几何信息, 没有视频流). This imposes a specific language in user-visible text without any opt-in, fallback, or documentation that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/sentence_boundaries.py (reported line 405)May include surrounding context.

python
"null",
        "-",
    ]
    proc = subprocess.run(cmd, capture_output=True, text=True)
    if proc.returncode != 0:
        raise RuntimeError(f"ffmpeg 切镜头检测失败: {video}: {proc.stderr.strip()[-500:]}")
    changes = set()

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file contains user-visible natural-language strings in Chinese, including the RuntimeError at L407 and log messages at L486 and L528. For a general-purpose skill, forcing a specific language in surfaced messages without offering a locale choice or documenting a justified locale constraint is a language-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code emits a natural-language message in Chinese for blocked clip boundaries. Because the file does not indicate that the skill is region-specific or that users can choose their preferred language, this appears to force a specific language without user opt-in.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/shot_review.py (reported line 89)May include surrounding context.

python
def probe_frame_clock(video):
    result = subprocess.run([
        "ffprobe", "-v", "error", "-select_streams", "v:0", "-show_frames",
        "-show_entries", "stream=time_base,start_pts,duration_ts:frame=pts,duration,pkt_duration",
        "-of", "json", str(video),

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
80% confidence
Finding

This subprocess call also avoids shell injection by using an argument list, but it passes attacker-influenced media content into ffmpeg for full decode and scene analysis. In the context of an agent skill that clips arbitrary user-supplied videos, this materially expands attack surface to a historically bug-prone native parser/decoder stack, creating risk of denial of service or exploitation through malformed media.

Content

Scanner excerpt · scripts/shot_review.py (reported line 157)May include surrounding context.

python
x, y, width, height = roi
        filters.append(f"crop={width}:{height}:{x}:{y}:exact=1")
    filters.extend([f"select='gt(scene,{threshold})'", "showinfo"])
    result = subprocess.run([
        "ffmpeg", "-hide_banner", "-nostdin", "-v", "info", "-xerror", "-copyts",
        "-threads", "2", "-i", str(video), "-map", "0:v:0",
        "-vf", ",".join(filters),

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The invalid-clip log messages are hard-coded in Chinese (for example, '跳过无效 clip' and '跳过过短 clip'). This creates a natural-language locale policy issue because the skill imposes a specific language in user-visible output without opt-in or any documented language selection.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest frames this skill as taking clip_plan.json and source video(s) to produce edited_source.mp4, with no mention of configuration via process environment. This module reads multiple environment variables that can materially change editing behavior, which is not an obvious requirement of the stated purpose and introduces an extra capability surface beyond the declared file-driven workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code emits a user-visible log message in Chinese (运行:) with no indication that language is configurable or optional. This is a natural-language locale policy concern because the skill unconditionally chooses a specific language for output rather than offering user choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill invokes external tools via subprocess for ffprobe/ffmpeg analysis, which is a safety-relevant operation under the code-file warning rule. Although the code is careful and read-only in intent, these calls have no confirmation prompt, user-facing log/print, or inline warning near execution explaining that external binaries will be run on the provided media.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This code performs file creation and replacement using a temporary file and os.replace, which is a covered file-write operation for code files. While the CLI requires an --output path and includes protective checks, there is no confirmation prompt or user-facing disclosure at the point of writing beyond the argument name itself.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.