Back to skill

Security audit

Product Demo Video Creator

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to make demo videos as advertised, but it needs review because it installs and runs broad system tools and passes customizable demo content into shell commands.

Install only after review, preferably in a disposable container or VM. Do not run the installer as root, avoid recording untrusted sites or entering secrets/customer data, pin and verify dependencies, and replace shell-string execSync calls with argument-array subprocess calls before using generated or third-party scene content.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/record-demo.mjs:137
Finding

Shell Command Injection Through Customizable Scene and Configuration Values

Content
View full analysis
/dev/null`); execSync(`ffmpeg -y -i ${workDir}/${s.id}_video.mp4 -i ${audioDir}/${s.id}.mp3 -c:v copy -c:a aac -b:a 128k -shortest ${workDir}/${s.id}_final.mp4 2>/dev/null`); execSync(`ffmpeg -y -i ${workDir}/${s.id}_final.mp4 -c:v libx264 -preset slow -crf ${crf} -pix_fmt yuv420p -r ${outputFps} -c:a aac -b:a 128k -ar 44100 -ac 2 ${workDir}/${s.id}_norm.mp4 2>/dev/null`); ``` ```javascript execSync(`ffmpeg -y -f concat -safe 0 -i ${workDir}/concat.txt -c copy ${outputPath} 2>/dev/null`); ``` ### Technical Analysis The script constructs shell command strings by directly interpolating customizable scene and configuration values. Affected values include scene narration, scene IDs, working-directory paths, voice configuration, and the output path. Escaping only double quotation marks in `s.narration` is insufficient. Shell constructs such as command substitution—`$(...)` and backticks—are still evaluated inside double-quoted shell strings. Other interpolated values are not quoted or validated at all, allowing whitespace and shell metacharacters to alter command structure. Because `execSync()` receives a string, Node.js executes it through a shell. The shell interprets attacker-controlled syntax before invoking ` ...[truncated 1477 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/install-deps.sh:8
Finding

Unpinned Global Third-Party Dependency Installation

Content
View full analysis
/dev/null && echo "✅ Puppeteer" || echo "⚠️ Puppeteer (may already exist)" # edge-tts (Microsoft Neural TTS - free) pip3 install edge-tts 2>/dev/null && echo "✅ edge-tts" || echo "⚠️ edge-tts" # Pillow (text overlays) pip3 install Pillow 2>/dev/null && echo "✅ Pillow" || echo "⚠️ Pillow (may already exist)" ``` The same unpinned installation approach is recommended in `SKILL.md`, lines 22-24: ```markdown | Puppeteer | Headless browser recording | `npm i -g puppeteer` | | edge-tts | Microsoft Neural TTS (free) | `pip3 install edge-tts` | | PIL/Pillow | Text overlays on frames | `pip3 install Pillow` (usually pre-installed) | ``` ### Technical Analysis The installer resolves the current registry versions of Puppeteer, `edge-tts`, and Pillow at installation time. No exact versions, lockfiles, package hashes, or integrity constraints are supplied. Consequently, the code reviewed during this audit does not fully determine the code that will execute when the installer is run. A compromised package, compromised publisher account, malicious transitive dependency, or unsafe future release could enter the environment without any change to this project. Puppeteer is installed globally, increasing its reach and making dependency state less reproducible. Package installation can also execute lifecycle or build hooks. If the installer is run with elevated privileges, such hooks inherit those privileges. ### Attack Path 1. A package registry, publisher account, package release, or transitive dependency is compromised. 2. The attacker publishes a malicious version that satisfies the unpinned install request. 3. A user runs `scripts/install-deps.sh`. 4. The package manager resolves and downloads ...[truncated 641 chars]
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/install-deps.sh:17
Finding

Unverified Remote FFmpeg Binary Is Installed and Executed

Content
View full analysis
/dev/null; then echo "📥 Downloading FFmpeg static build..." curl -sL https://johnvansickle.com/ffmpeg/releases/ffmpeg-release-amd64-static.tar.xz -o /tmp/ffmpeg.tar.xz tar xf /tmp/ffmpeg.tar.xz -C /tmp/ cp /tmp/ffmpeg-*-amd64-static/ffmpeg /usr/local/bin/ cp /tmp/ffmpeg-*-amd64-static/ffprobe /usr/local/bin/ rm -rf /tmp/ffmpeg.tar.xz /tmp/ffmpeg-*-amd64-static echo "✅ FFmpeg" else echo "✅ FFmpeg (already installed)" fi ``` ### Technical Analysis The installer downloads a mutable archive from an external website and extracts its contents without verifying a cryptographic signature or a pinned checksum. It then copies the resulting `ffmpeg` and `ffprobe` executables into `/usr/local/bin`. HTTPS protects the connection in transit but does not establish that the downloaded artifact matches a version reviewed by this project. A compromised distribution server, publishing process, DNS/TLS trust path, or upstream artifact could substitute attacker-controlled binaries. The archive URL is not version-pinned. Therefore, its contents may change after the Skill has been audited. The recorder later invokes `ffmpeg` and `ffprobe` repeatedly, turning artifact substitution into executable-code delivery. ### Attack Path 1. The remote FFmpeg distribution source or its delivery path is compromised, or the mutable artifact is replaced. 2. A user without an existing `ffmpeg` binary runs `scripts/install-deps.sh`. 3. `curl` downloads the attacker-controlled archive. 4. The installer extracts it without signature or checksum validation. 5. The attacker-controlled executables are copied into `/usr/local/bin`. 6. `scripts/record-demo.mjs` later invokes `ffmpeg` or `ffp ...[truncated 621 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/record-demo.mjs:150
Finding

Chromium Sandbox Disabled While Loading Configurable Websites

Content
View full analysis
fs.unlinkSync(`${dir}/${f}`)); } catch(e) {} await page.goto(s.url, { waitUntil: 'networkidle2', timeout: 30000 }); ``` ### Technical Analysis The browser is launched with both `--no-sandbox` and `--disable-setuid-sandbox`, disabling Chromium's principal process-isolation security boundary. At the same time, scene URLs are explicitly intended to be customized, and each configured page is loaded and allowed to execute browser content. Disabling the sandbox does not by itself create a browser vulnerability, but it materially increases the impact of a renderer or browser-engine exploit. A malicious or compromised page that achieves code execution inside Chromium has fewer containment boundaries to escape before reaching the recorder account's operating-system privileges. The documentation also presents `--no-sandbox` as a troubleshooting measure, which may normalize an unsafe default rather than restricting it to exceptional isolated environments. ### Attack Path 1. An attacker controls a configured scene URL, compromises the legitimate target site, or causes it to serve malicious third-party content. 2. Puppeteer opens the page in Chromium. 3. The page exploits a vulnerability in Chromium or one of its rendering components. 4. Because the browser sandbox has been di ...[truncated 815 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
2. Define scenes in `scripts/record-demo.mjs` (copy template, customize)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
2. Define scenes in `scripts/record-demo.mjs` (copy template, customize)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 163)May include surrounding context.

md
2. Define scenes in `scripts/record-demo.mjs` (copy template, customize)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/install-deps.sh (reported line 23)May include surrounding context.

sh
tar xf /tmp/ffmpeg.tar.xz -C /tmp/
  cp /tmp/ffmpeg-*-amd64-static/ffmpeg /usr/local/bin/
  cp /tmp/ffmpeg-*-amd64-static/ffprobe /usr/local/bin/
  rm -rf /tmp/ffmpeg.tar.xz /tmp/ffmpeg-*-amd64-static
  echo "✅ FFmpeg"
else
  echo "✅ FFmpeg (already installed)"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/install-deps.sh (reported line 23)May include surrounding context.

sh
tar xf /tmp/ffmpeg.tar.xz -C /tmp/
  cp /tmp/ffmpeg-*-amd64-static/ffmpeg /usr/local/bin/
  cp /tmp/ffmpeg-*-amd64-static/ffprobe /usr/local/bin/
  rm -rf /tmp/ffmpeg.tar.xz /tmp/ffmpeg-*-amd64-static
  echo "✅ FFmpeg"
else
  echo "✅ FFmpeg (already installed)"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/install-deps.sh (reported line 23)May include surrounding context.

sh
tar xf /tmp/ffmpeg.tar.xz -C /tmp/
  cp /tmp/ffmpeg-*-amd64-static/ffmpeg /usr/local/bin/
  cp /tmp/ffmpeg-*-amd64-static/ffprobe /usr/local/bin/
  rm -rf /tmp/ffmpeg.tar.xz /tmp/ffmpeg-*-amd64-static
  echo "✅ FFmpeg"
else
  echo "✅ FFmpeg (already installed)"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill describes running shell commands, installing global packages, invoking FFmpeg, and executing Node/Python scripts, but it does not declare any explicit tool scope or permissions boundary. That makes the skill harder to sandbox and review, and increases the risk that an agent executes file or shell operations beyond what a user expects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs users to automate browser interactions against arbitrary external URLs, including entering content into forms, but it does not warn that entered data will be transmitted to those sites. In this context, a user could unknowingly paste sensitive or proprietary content into third-party applications while recording a demo.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill recommends edge-tts for narration generation but does not clearly disclose that the narration text is sent to Microsoft servers. This creates a privacy and data-handling risk because scripts, product messaging, or internal information may be exfiltrated to a third-party service without explicit user awareness.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The section 'Voice Selection (edge-tts)' exclusively recommends en-US voices and the example command uses an English utterance, which amounts to a language preference in natural-language guidance. Because the document does not offer alternatives or state that the guide is specifically for US-English demos, it violates the policy against forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script downloads, extracts, copies binaries into /usr/local/bin, and installs packages/fonts without any explicit warning that it modifies the host system and may require elevated privileges. In a skill intended for broad automation use, this can lead users or agents to make persistent system changes unexpectedly, increasing operational and supply-chain risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code executes multiple external commands via execSync (edge-tts, ffprobe, ffmpeg, python3) and writes generated files under /tmp and the output path. Although there are progress logs, they do not disclose the safety-relevant behaviors such as shell execution, creation of temporary files, and overwriting output with ffmpeg -y, and the header comment also does not warn about these actions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The generated overlay hard-codes the claim '100% Client-Side', but the script itself drives a real browser to remote URLs and generates audio via external tooling, so it does not verify or enforce that privacy property. This can mislead viewers into trusting a product's data handling based on marketing text rather than measured behavior, especially when the recorded app may transmit data over the network.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The natural-language guidance specifies only en-US voices and labels them as the recommended options, with no indication that users may select other languages or locales. This can violate language/locale policy expectations when a skill implicitly forces a specific locale without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The configuration forces the voice to en-US-AndrewNeural, which imposes a specific language and locale choice. There is no indication in the script's interface or comments that users can opt into or choose an alternate language/locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The overlay generator inserts the fixed English text '100% Client-Side' into all tool scenes. This embeds a specific language choice into output artifacts without any user language selection or documented locale constraint.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/record-demo.mjs:142