Back to skill

Security audit

dy-caption

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned, but it runs an unpinned npm package at runtime while handling API keys and video links.

Install only if you are comfortable trusting the live Videosays npm package and service. Prefer a pinned, reviewed version or lockfile-managed local install, and run it in a least-privileged environment because the setup/transcription flow handles an API key, stores it under `~/.videosays`, and sends video links plus the key to Videosays.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
scripts/dytext.sh:7
Finding

Unpinned npm Package Is Retrieved and Executed Through npx

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (17)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README instructs users to run npx videosays setup without pinning a specific package version. Because npx resolves and executes the latest published package by default, a compromised maintainer account, malicious new release, or dependency hijack could result in arbitrary code execution on the user's machine. In this skill's context, the command is part of first-time setup and handles API key onboarding, which increases sensitivity and makes the unpinned execution path more dangerous.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill documentation tells users to execute npx videosays without version pinning, which causes retrieval and execution of whatever version is current on the npm registry at runtime. If the npm package or its supply chain is compromised, this becomes a direct arbitrary code execution vector. Since this skill is specifically guiding users to run the command on shared workstation environments used for agent tooling, the risk is elevated beyond a purely informational mention.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This README example uses npx videosays transcribe without specifying an exact version, exposing users to execution of unreviewed future package contents. npx is effectively a remote code execution mechanism when used this way, and compromise of the package publisher or dependencies could lead to malware execution, credential theft, or local data access. The context is more dangerous because the tool processes user-supplied links and may run in environments with access to agent workspace data and stored secrets.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The command example relies on unpinned npx videosays, which can silently execute a newly published package version. That creates a supply-chain execution risk: an attacker controlling the package or a dependency could run arbitrary code under the user's privileges. Because the command is presented as normal usage rather than an explicitly reviewed install step, users are likely to copy-paste it without scrutiny.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The README documents npx videosays balance without a pinned version, meaning the latest registry version will be fetched and executed at runtime. While the balance command may seem low-risk functionally, the underlying execution risk is the same: arbitrary code from a compromised package could access local files, environment variables, or tokens. The impact is somewhat lower than setup because it is less directly tied to credential onboarding, but still constitutes a real supply-chain vulnerability.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The history example invokes npx videosays history 20 without pinning the package version, which exposes users to execution of arbitrary future package contents. Any supply-chain compromise could abuse the command invocation to harvest local credentials or modify files. Although the business function is only reading history, the security boundary is the package execution itself, not the advertised subcommand.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The architecture section references npx videosays as the execution mechanism without noting version pinning or other safeguards. This normalizes runtime execution of the latest npm package and obscures the supply-chain trust assumption from users. In the context of an agent skill that may be adopted by non-expert users, that omission increases the likelihood of unsafe copy-paste use.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill declares a dependency on npx, which fetches and executes packages at runtime without pinning an exact package version or integrity hash. This creates a supply-chain risk: a compromised upstream package, malicious new release, or dependency confusion event could cause arbitrary code execution in the agent environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
99% confidence
Finding

The command npx videosays executes an npm package without pinning a specific version, so the skill will typically resolve the latest published release at runtime. In this skill, that package handles API keys and user-supplied video links, so a malicious or compromised upstream release could exfiltrate secrets or execute arbitrary code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
99% confidence
Finding

npx videosays setup pulls and runs the package at runtime without version pinning, which is especially risky because the setup flow stores credentials in ~/.videosays. If the upstream package or one of its dependencies is compromised, the setup step could steal API keys or modify local configuration maliciously.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
99% confidence
Finding

The unpinned npx videosays transcribe command introduces runtime supply-chain exposure and processes user-controlled input. Because the tool sends API keys and video links to a remote service, a malicious update could capture credentials, alter outputs, or execute arbitrary local actions before or after contacting the API.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
99% confidence
Finding

This transcribe example again relies on npx videosays without a pinned version, allowing whatever package version npm resolves at execution time to run in the agent context. Given that the command accepts arbitrary pasted content and likely parses URLs, any malicious upstream update would have access to user input, local environment data, and network egress.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

npx videosays balance still executes unpinned code from npm at runtime. Even though this subcommand is less sensitive than transcription, it can still access local credentials and environment state, so a compromised release could leak API keys or perform arbitrary actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The npx videosays history command is also unpinned and therefore subject to the same runtime package substitution risk as the other commands. A malicious package version could read transcription history, harvest stored API keys, and exfiltrate account metadata.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The documentation explicitly states that the skill uses npx videosays to send API keys and video links to a third-party API, but the package doing so is not pinned to a specific version. That combination increases the danger: a supply-chain compromise would expose both sensitive credentials and user content to arbitrary malicious code executed locally before the network request is even made.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

exec npx videosays "$@" executes a package by name without pinning a specific version, which can cause the script to fetch and run whatever version npx resolves at runtime. If the upstream package is compromised, a malicious version is published, or dependency resolution is tampered with, this skill could execute attacker-controlled code on the host. The skill context makes this more dangerous because the script is a thin wrapper whose entire trust boundary depends on the external package.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.