Back to skill

Security audit

视频自动剪辑助手

Security checks for vulnerabilities and agentic risk

Overview

This video-editing skill appears mostly purpose-related, but its documentation overstates capabilities and under-discloses package-install, privacy, and file-overwrite risks.

Review this skill before installing. Use it only on media files and output directories you choose, avoid running the optional unpinned pip installs in a privileged or shared Python environment, and do not use API-based ASR providers for private recordings unless you are comfortable sending audio or video to that provider.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:171
Finding

Unpinned Third-Party Package Installation Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 171–174
Vulnerability Type: Supply-chain exposure through unpinned dependencies
Risk Level: Medium

Vulnerable Code

bash
pip install funclip
pip install openai-whisper

Technical Analysis

The installation instructions retrieve mutable third-party packages from the user's configured Python package index without specifying reviewed versions, package hashes, a lockfile, or a trusted index URL. Consequently, the code installed by these commands may differ between executions and cannot be verified against a known-good artifact.

This creates exposure to compromised upstream releases, package-index substitution, dependency confusion involving transitive packages, or a malicious package served by an untrusted configured mirror. A malicious source distribution or build dependency may execute code during package installation, while malicious installed modules may execute when subsequently imported.

Attack Path

  1. An attacker compromises an upstream package, one of its transitive dependencies, or a package index used by the victim.
  2. The attacker publishes or serves a malicious release under a dependency name resolved by pip.
  3. A user follows the Skill documentation and runs one of the unpinned installation commands.
  4. Pip resolves the mutable dependency graph and downloads the attacker-controlled release.
  5. Malicious code executes during the package build or later when the installed package is imported and used.

Impact Assessment

Successful exploitation can execute code with the privileges of the user performing the installation or running the installed package. This may permit access to that user's files, environment variables, credentials available to the process, and the active Python environment. If installation is performed with elevated privileges, the impact can extend to system-wide Python packages and files accessible to th ...[truncated 22 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to a reviewed, exact version.
  2. Maintain a lockfile that also fixes all transitive dependency versions.
  3. Require package hashes, such as through a hash-locked requirements file and pip's --require-hashes option.
  4. Explicitly document and enforce a trusted package index rather than relying on arbitrary user or environment configuration.
  5. Install dependencies in an isolated virtual environment under a non-privileged account.
  6. Review package provenance, release signatures where available, build dependencies, and transitive dependencies before updating pins.
  7. Add automated dependency vulnerability and integrity scanning to the release process.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/burn_subtitles.py:18
Finding

Predictable Temporary Subtitle File Allows Conditional File Overwrite

Content
View full analysis

Vulnerability Details

File Location: scripts/burn_subtitles.py, lines 18–23
Vulnerability Type: Unsafe temporary-file creation and symlink following
Risk Level: Medium

Vulnerable Code

python
tmp = srt_file + ".utf8.srt"
with open(srt_file, "r", encoding="gbk", errors="ignore") as src:
    content = src.read()
with open(tmp, "w", encoding="utf-8") as dst:
    dst.write(content)
srt_file = tmp

Technical Analysis

When UTF-8 decoding fails, the script creates a converted subtitle file at the deterministic path <original-path>.utf8.srt. The file is opened in write mode without exclusive creation, symlink rejection, restrictive explicit permissions, or verification that the destination is a newly created regular file.

Python's ordinary open(..., "w") follows symbolic links and truncates an existing target. Therefore, if an attacker can write to the subtitle file's directory, the attacker can pre-create the predictable destination as a symbolic link to another file writable by the victim. The script will then follow that link and replace the target's contents with converted subtitle data.

The generated file is also not removed after FFmpeg finishes, leaving an unnecessary persistent copy of the subtitle content.

Attack Path

  1. The attacker obtains write access to the directory containing an attacker-supplied or otherwise predictable subtitle file.
  2. The attacker determines the destination path by appending .utf8.srt to the subtitle filename.
  3. The attacker creates that destination as a symbolic link to a file writable by the victim process.
  4. The victim invokes burn_subtitles.py with a subtitle file that fails UTF-8 decoding and triggers the GBK conversion branch.
  5. The script opens the predictable destination in write mode, follows the symbolic link, and truncates the linked target.
  6. The script writes subtitle content into the target file, potentially corrupting con ...[truncated 763 chars]
Remediation
View remediation

Remediation Suggestions

  1. Create the converted subtitle with tempfile.NamedTemporaryFile or tempfile.mkstemp rather than deriving a predictable adjacent filename.
  2. Ensure exclusive creation and restrictive permissions, such as mode 0600, and reject symbolic links where platform facilities allow it.
  3. Keep the temporary file descriptor under application control while writing the converted content.
  4. Pass the securely generated path to FFmpeg only after writing and closing the file safely.
  5. Remove the temporary file in a finally block regardless of FFmpeg success or failure.
  6. Avoid placing temporary files in attacker-writable directories when a private application-controlled directory is available.
  7. Validate that the generated destination is a regular file and is owned by the expected user before use.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a broad automated video editing assistant with capabilities such as extracting highlights, generating subtitles, trimming clips, producing short videos, and summarizing content. However, the supplied code implements a much narrower function: taking an input video and an existing SRT file, then burning those subtitles into the video via FFmpeg. It does not analyze video content, extract segments, generate subtitles from audio, create summaries, or perform automated clipping/export workflows. While subtitle burn-in is loosely related to the declared domain, the primary purpose and functional scope of this code chunk are materially narrower than the description, so this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个功能较完整的“自动视频剪辑助手”,重点包含自动分析内容、提取精彩片段、生成字幕和摘要等高级能力。但提供的代码并未进行任何内容分析、语音识别、字幕处理、摘要生成或平台导出适配。它只接收用户明确提供的时间参数或片段区间,调用 ffmpeg 执行基础视频切割。虽然“裁剪时长”这一点与声明部分重合,但整体主功能明显比声明狭窄,且缺失声明中的关键自动化与字幕/摘要能力,因此描述与实际行为存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a broad 'automatic video editing' skill with highlight extraction, subtitle generation/burn-in, keyword clip extraction, and summary creation. The supplied code only performs two concrete operations: duration trimming and format conversion/resizing for social-media aspect ratios using FFmpeg. While 'trim duration,' 'create short videos,' and 'multi-platform export' are partially represented, the major advertised capabilities are absent. Therefore the description materially overstates the behavior of this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The supplied code is narrowly focused on one function: detecting scene changes and extracting several highlight clips with FFmpeg. It gets video metadata, finds scene timestamps, filters them by minimum spacing, and exports clips. It does not generate subtitles, burn subtitles into video, create platform-specific exports, perform keyword extraction, generate summaries, or provide a broader automatic editing pipeline. Since the declared description presents a substantially broader multi-function video auto-editing assistant than what this code actually implements, this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents shell-based video processing workflows and implies file read/write behavior, but it does not declare any explicit tool scope or permission boundaries. This is dangerous because an agent may invoke shell and filesystem capabilities more broadly than users expect, increasing the risk of unintended command execution or file access when handling user-supplied paths and media files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs users to generate subtitles using external ASR providers such as Whisper API/FunClip-related services without warning that audio or video content may leave the local environment. This creates a privacy and data-governance risk, especially for meetings, interviews, or proprietary recordings containing sensitive speech.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's docstrings, argument descriptions, status messages, and errors are all presented in Chinese, which imposes a specific language on users. There is no opt-in, alternate locale, or documentation that this skill is intentionally restricted to a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code writes a temporary UTF-8 subtitle file at L21-L22 and invokes ffmpeg with -y at L31, which forces overwriting the output file at L36 if it already exists. Although the script purpose implies video processing, there is no user-facing warning, confirmation, or descriptive note that existing files may be created or overwritten.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/export_social.py (reported line 21)May include surrounding context.

python
"-c:a", "aac",
        output
    ]
    return subprocess.run(cmd, capture_output=True).returncode == 0

def scale_and_pad(input_file: str, target_size: str, output: str) -> bool:
    """缩放并填充黑边以适应目标比例。"""

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/extract_highlights.py (reported line 52)May include surrounding context.

python
"-c:a", "aac",
        output
    ]
    return subprocess.run(cmd, capture_output=True).returncode == 0

def scale_and_pad(input_file: str, target_size: str, output: str) -> bool:
    """缩放并填充黑边以适应目标比例。"""

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/export_social.py (reported line 34)May include surrounding context.

python
"-c:a", "aac",
        output
    ]
    return subprocess.run(cmd, capture_output=True, text=True).returncode == 0

def export(input_file: str, fmt: str, duration: float, output_dir: str) -> list:
    os.makedirs(output_dir, exist_ok=True)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file contains natural-language strings entirely in Chinese, including the module description, help text, and runtime messages. Under the policy criteria, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/burn_subtitles.py (reported line 38)May include surrounding context.

python
"ffprobe", "-v", "quiet", "-print_format", "json",
        "-show_format", "-show_streams", input_file
    ]
    result = subprocess.run(cmd, capture_output=True, text=True)
    if result.returncode != 0:
        return {}
    try:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/burn_subtitles.py (reported line 49)May include surrounding context.

python
"ffprobe", "-v", "quiet", "-print_format", "json",
        "-show_format", "-show_streams", input_file
    ]
    result = subprocess.run(cmd, capture_output=True, text=True)
    if result.returncode != 0:
        return {}
    try:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/cut_video.py (reported line 17)May include surrounding context.

python
"ffprobe", "-v", "quiet", "-print_format", "json",
        "-show_format", "-show_streams", input_file
    ]
    result = subprocess.run(cmd, capture_output=True, text=True)
    if result.returncode != 0:
        return {}
    try:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/extract_highlights.py (reported line 12)May include surrounding context.

python
"ffprobe", "-v", "quiet", "-print_format", "json",
        "-show_format", "-show_streams", input_file
    ]
    result = subprocess.run(cmd, capture_output=True, text=True)
    if result.returncode != 0:
        return {}
    try:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/extract_highlights.py (reported line 35)May include surrounding context.

python
"ffprobe", "-v", "quiet", "-print_format", "json",
        "-show_format", "-show_streams", input_file
    ]
    result = subprocess.run(cmd, capture_output=True, text=True)
    if result.returncode != 0:
        return {}
    try:

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language description and most operational guidance are presented only in Chinese, which effectively forces a specific language for users without any opt-in or stated regional constraint. The policy explicitly allows fixed language only when users are given a choice or the locale limitation is justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s natural-language strings and docstrings are written in Chinese, including the tool description and usage text, with no indication that users may choose another language. This can violate a language/locale policy when a skill imposes a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This Python file contains user-facing descriptions, help text, and status messages entirely in Chinese, including the module docstring and CLI output. Under the policy rule, forcing a specific language without user opt-in is a natural-language locale violation unless the constraint is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.