Back to skill

Security audit

video-summarize

Security checks for vulnerabilities and agentic risk

Overview

This video-summary skill is mostly purpose-aligned, but it uses Chrome browser cookies automatically for YouTube and can run mutable remote installers during setup, which merits careful review before installation.

Install only if you are comfortable with a shell-based setup that may install Homebrew/packages, modify your shell profile, download unpinned dependencies, store transcripts locally, and let yt-dlp read Chrome cookies for YouTube. Prefer reviewing the scripts first, removing automatic browser-cookie use, and handling Homebrew/dependencies manually or with pinned verified versions.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/install_dependency.sh:16
Finding

Unverified Remote Shell Script Download and Execution

Content
View full analysis
/dev/null; then echo "✅ Homebrew 已安装" else echo "❌ Homebrew 未安装" echo "正在安装 Homebrew(可能需要几分钟)..." /bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)" # 添加 brew 到 PATH(Apple Silicon Mac) if [[ -d "/opt/homebrew/bin" ]] && ! grep -q "/opt/homebrew/bin" ~/.zshrc 2>/dev/null; then echo 'eval "$(/opt/homebrew/bin/brew shellenv)"' >> ~/.zshrc eval "$(/opt/homebrew/bin/brew shellenv)" fi echo "✅ Homebrew 安装完成" fi ``` ### Technical Analysis The installer retrieves a shell script from a remote URL and passes the returned content directly to `/bin/bash`. The URL references the mutable `HEAD` branch, so the effective code executed by the Skill can change after the Skill itself has been reviewed. Although the URL belongs to Homebrew's official GitHub repository rather than a personal paste site, the implementation provides no commit pinning, checksum verification, signature validation, local review step, or trusted-content boundary. Consequently, the locally reviewed package does not fully determine what commands are executed during installation. The remote Homebrew installer can perform system-level package-manager setup and may request elevated privileges depending on the host configuration. Automatically installing an entire package manager also exceeds the minimum setup action necessary when Homebrew is absent; the safer behavior is to stop and ask the user to install or approve it separately. ### Attack Path 1. A user follows the documented setup instructions and runs `scripts/install_dependency.sh`. 2. The script determines that `brew` is unavaila ...[truncated 1391 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/process.sh:28
Finding

Automatic Access to Chrome Browser Cookies Exceeds Declared Requirements

Content
View full analysis
/dev/null || echo "未知标题") VIDEO_ID=$(yt-dlp $YTDLP_COOKIES --get-id --no-playlist "$VIDEO_URL" 2>/dev/null || echo "unknown") ``` ```bash yt-dlp \ $YTDLP_COOKIES \ --write-subs \ --write-auto-subs \ --sub-langs "zh-Hans,zh-CN,en" \ --skip-download \ --output "${SUBS_DIR}/${SAFE_TITLE}" \ --no-playlist \ --no-warning \ "$VIDEO_URL" 2>&1 | grep -E "(Downloading|Writing|has no)" | tail -5 || true ``` ```bash yt-dlp \ $YTDLP_COOKIES \ --format "bestaudio/best" \ --extract-audio \ --output "${AUDIO_FILE}" \ --no-playlist \ --no-warning \ "$VIDEO_URL" 2>&1 | tail -5 ``` ### Technical Analysis For any input string containing `youtube.com` or `youtu.be`, the script directs `yt-dlp` to extract cookies from the user's Chrome profile. Browser cookies are sensitive authentication material and can represent active account sessions. This behavior exceeds the Skill's declared minimum privilege requirements. Both Skill documents state that only public videos are processed, for which authenticated browser cookies should not ordinarily be required. The documentation also does not clearly disclose that running the processor causes a third-party executable to access the Chrome cookie database. The trigger uses a regular-expression substring match against the complete unparsed URL rather than validating the URL's scheme and hostname. Inp ...[truncated 2103 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/install_dependency.sh:63
Finding

Unpinned and Unverified Third-Party Dependencies and Model Artifact

Content
View full analysis
/dev/null; then YTDLP_VERSION=$(pip show yt-dlp | grep Version | cut -d' ' -f2) echo "✅ yt-dlp 已安装: $YTDLP_VERSION" else pip install --upgrade pip -q pip install yt-dlp -q echo "✅ yt-dlp 安装完成" fi ``` ```bash if command -v whisper-cli &> /dev/null; then echo "✅ whisper.cpp 已安装" else brew install whisper-cpp echo "✅ whisper.cpp 安装完成" fi ``` ```bash mkdir -p "$MODELS_DIR" MODEL_FILE="$MODELS_DIR/ggml-base.bin" if [ -f "$MODEL_FILE" ]; then echo "✅ 模型已存在: $MODEL_FILE" else echo "下载 ggml-base.bin (约 148MB)..." curl -L -o "$MODEL_FILE" \ "https://huggingface.co/ggerganov/whisper.cpp/resolve/main/ggml-base.bin" echo "✅ 模型下载完成" fi ``` ```bash if command -v ffmpeg &> /dev/null; then echo "✅ ffmpeg 已安装" else brew install ffmpeg echo "✅ ffmpeg 安装完成" fi ``` ### Technical Analysis The installer retrieves and installs the latest available versions of `pip`, `yt-dlp`, `whisper-cpp`, and `ffmpeg` instead of versions reviewed with the Skill. It also downloads the Whisper model through a mutable `main` reference and performs no checksum or signature verification. As a result, two installations of the same audited Skill can receive materially different dependency code or model data. The local audit therefore cannot establish the exact behavior of the components that will execute. The Python virtual environment limits package placement but does not sandbox package installation or runtime behavior. Python packages may execute installation-related code, and `yt-dlp` subsequently receives attacker-controlled URLs while also potentially receiving browser-cookie access. Homebrew packages install native executables that run with the user's privileges. The ...[truncated 1804 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared purpose is simple video summarization, but the documented behavior includes downloading third-party content, persistent caching, transcript storage, and possibly use of browser-derived authentication material as indicated by the static finding. Hidden or under-declared behaviors are risky because they can expose private data, retain copyrighted or sensitive content locally, and cause an agent to perform actions the user did not knowingly authorize.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is simple video summarization, but the documented behavior includes downloading third-party content, persistent caching, transcript storage, and possibly use of browser-derived authentication material as indicated by the static finding. Hidden or under-declared behaviors are risky because they can expose private data, retain copyrighted or sensitive content locally, and cause an agent to perform actions the user did not knowingly authorize.

Content

No source excerpt is available for this finding.

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
90% confidence
Finding

Using --cookies-from-browser chrome matches credential-access behavior because it reads browser-stored authentication material from the local profile. While the apparent purpose is to access YouTube content that requires login rather than to steal credentials, this is still dangerous in an agent skill because it normalizes secret access from the host environment and may expose private session context or enable unintended authenticated requests.

Content

Scanner excerpt · scripts/process.sh (reported line 31)May include surrounding context.

sh
/cache"
RESULT_DIR="$SKILL_DIR/summarize_result"

# 检查环境
if [ ! -d "$VENV_DIR" ]; then
    echo "❌ 环境未安装,请先运行: scripts/install_dependency.sh"
    exit 1
fi

# 激活虚拟环境
source "$VENV_DIR/bin/activate"

# 参数
VIDEO_URL="$1"

# 检测是否是 YouTube 链接(需要 cookies)
YTDLP_COOKIES=""
if [[ "$VIDEO_URL" =~ youtube\.com|youtu\.be ]]; then
    YTDLP_COOKIES="--cookies-from-browser chrome"
    echo "ℹ️ YouTube 链接,将使用 Chrome cookies"
fi

if [ -z "$VIDEO_URL" ]; then
    echo "用法: process.sh <视频链接>"
    echo ""
    echo "支持平台:"
    echo "  B站: https://www.bilibili.com/video/BVxxx"
    echo "  YouTube: https://www.youtube.com/watch?v=xxx"
    echo "  抖音: https://www.douyin.com/video/xxx"
    echo "  Twitter/X: https://twitter.com/user/status/xxx"
    echo "  TikTok: https://www.tiktok.com/@user/video/xxx"
    echo "  Instagram: https://www.instagram.com/p/xxx"
    echo "  其他: yt-dlp 支持的任

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/process.sh (reported line 234)May include surrounding context.

sh
rm -rf "$SUBS_DIR"
rm -f "$AUDIO_FILE" "$WAV_FILE" "$STATUS_FILE"
# 如果 whisper 生成了临时文件也清理
rm -f "$WORK_DIR/transcript.txt"
# 注意:transcript_raw.txt 保留不删除

echo ""

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly relies on network access to third-party video platforms and tools like yt-dlp to fetch subtitles or audio, but it does not clearly warn users that submitting a URL causes remote retrieval and processing of video-related data. This can expose user interests, internal links, or sensitive video references to external services without informed consent, especially if users provide non-public or sensitive URLs by mistake.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill documents local caching and output paths for transcripts and summaries, but it does not clearly warn users that these files may persist on disk and retain sensitive spoken content from processed videos. In shared environments or on developer workstations, leftover transcripts, summaries, and cache artifacts can disclose confidential information to other users or later processes.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises and instructs shell-based execution of local scripts and dependency installation, but it does not declare any explicit tool scope or permissions. This increases the chance that an agent invokes shell access implicitly and with broader authority than the user expects, which is dangerous because the workflow includes network downloads, local file writes, and package installation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger condition is broad enough to match common requests involving video links and summaries, which can cause the skill to activate unexpectedly. Over-broad triggering is dangerous in a shell-capable skill because it may initiate network downloads, local writes, and transcription workflows without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description does not clearly warn users that video URLs and fetched content are sent to external tools/services and that transcripts/results are stored on disk. This is a privacy and transparency problem because users may provide sensitive or private links without realizing content will be downloaded, transcribed, cached, and retained locally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This shell script presents its user-facing messages, installation progress, and usage instructions entirely in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

The script downloads a remote installer with curl and immediately executes it via /bin/bash -c, which is a classic arbitrary remote code execution pattern. If the upstream URL, network path, or hosting account is compromised, running the skill installer would execute attacker-controlled code on the host.

Content

Scanner excerpt · scripts/install_dependency.sh (reported line 23)May include surrounding context.

sh
else
    echo "❌ Homebrew 未安装"
    echo "正在安装 Homebrew(可能需要几分钟)..."
    /bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)"
    
    # 添加 brew 到 PATH(Apple Silicon Mac)
    if [[ -d "/opt/homebrew/bin" ]] && ! grep -q "/opt/homebrew/bin" ~/.zshrc 2>/dev/null; then

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The installer performs system-wide changes beyond the skill’s isolated runtime by installing Homebrew and modifying the user’s shell profile (~/.zshrc). This expands the skill’s footprint, persists changes outside the skill directory, and increases supply-chain and host-integrity risk if the installation path or fetched installer is compromised.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/install_dependency.sh (reported line 83)May include surrounding context.

sh
# ===== 步骤 6: 下载 Whisper 模型 =====
echo ""
echo "[6/7] 下载 Whisper base 模型..."
mkdir -p "$MODELS_DIR"
MODEL_FILE="$MODELS_DIR/ggml-base.bin"

if [ -f "$MODEL_FILE" ]; then

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script automatically enables yt-dlp's --cookies-from-browser chrome for YouTube URLs, which accesses authenticated browser session data without an explicit upfront consent flow or strong warning. In this skill context, that is sensitive because browser cookies are credential material and could expose private account context, age-restricted content access, or subscription/authenticated data to downstream tooling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The header comments present the skill description entirely in Chinese, and the script continues to use Chinese-only user-facing messages throughout execution. This forces a specific language experience without any indication that users can choose another language, which is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file uses Chinese-only natural-language text in the module docstring and CLI usage output, which imposes a specific language on users. Under the policy, a fixed language is only acceptable when the skill offers user choice or clearly documents a justified locale-specific constraint, neither of which is present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.