T09 · Insecure Skill Coding Practices
- Location
scripts/scrapling.sh:17- Finding
Arbitrary Python Code Execution Through Unsafe URL Interpolation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a real Remotion video workflow, but it also makes website scraping and public dev-server exposure routine, and one helper script has unsafe input handling that could allow code execution from a crafted URL.
Install only if you are comfortable with the agent scraping user-specified websites, downloading remote assets, using third-party screenshot services, installing unpinned npm/pip packages, and potentially exposing a local Remotion Studio to the public internet. Prefer reviewing or patching the scripts first, pinning dependencies, using local preview by default, and requiring explicit approval before any scraping, external screenshot service, or tunnel is used.
scripts/scrapling.sh:17Arbitrary Python Code Execution Through Unsafe URL Interpolation
scripts/scrapling.sh:92Shell Command Injection Through Unescaped Scraped Metadata
scripts/remotion.sh:12Execution of Mutable and Unpinned Third-Party Packages
SKILL.md:197Mandatory Public Exposure of an Unauthenticated Development Server
The skill is described as a video-generation workflow, but it also mandates website scraping, third-party screenshot retrieval, remote asset downloading, and public tunneling. This mismatch hides materially riskier behaviors behind an innocuous description, making unsafe actions more likely to be performed without informed approval.
Publicly exposing the local Remotion development server through a tunnel without a clear safety warning can leak project content and create a reachable service on the internet. Because this is presented as a routine step, users may not realize they are publishing a local service beyond their machine.
The skill clearly instructs network-capable actions including web scraping, asset downloads, and third-party tunnel exposure, but it declares no explicit tool scope or permissions boundary. That increases the chance an agent will perform outbound requests or public exposure without user awareness or policy enforcement.
Using npx remotion without pinning an exact version allows whatever package version resolves at execution time to run. This creates a supply-chain risk where unexpected upstream changes or a compromised package version could execute arbitrary code in the build environment.
Using npx remotion without pinning an exact version allows whatever package version resolves at execution time to run. This creates a supply-chain risk where unexpected upstream changes or a compromised package version could execute arbitrary code in the build environment.
Using npx remotion without pinning an exact version allows whatever package version resolves at execution time to run. This creates a supply-chain risk where unexpected upstream changes or a compromised package version could execute arbitrary code in the build environment.
Using npx remotion without pinning an exact version allows whatever package version resolves at execution time to run. This creates a supply-chain risk where unexpected upstream changes or a compromised package version could execute arbitrary code in the build environment.
Using npx remotion without pinning an exact version allows whatever package version resolves at execution time to run. This creates a supply-chain risk where unexpected upstream changes or a compromised package version could execute arbitrary code in the build environment.
Using npx remotion without pinning an exact version allows whatever package version resolves at execution time to run. This creates a supply-chain risk where unexpected upstream changes or a compromised package version could execute arbitrary code in the build environment.
Using npx remotion without pinning an exact version allows whatever package version resolves at execution time to run. This creates a supply-chain risk where unexpected upstream changes or a compromised package version could execute arbitrary code in the build environment.
Using npx remotion without pinning an exact version allows whatever package version resolves at execution time to run. This creates a supply-chain risk where unexpected upstream changes or a compromised package version could execute arbitrary code in the build environment.
Using npx remotion without pinning an exact version allows whatever package version resolves at execution time to run. This creates a supply-chain risk where unexpected upstream changes or a compromised package version could execute arbitrary code in the build environment.
Using npx remotion without pinning an exact version allows whatever package version resolves at execution time to run. This creates a supply-chain risk where unexpected upstream changes or a compromised package version could execute arbitrary code in the build environment.
Using npx remotion without pinning an exact version allows whatever package version resolves at execution time to run. This creates a supply-chain risk where unexpected upstream changes or a compromised package version could execute arbitrary code in the build environment.
The documentation broadens a local video tool into a workflow that scrapes external sites and exposes a local dev server to the public internet. Expanding scope in documentation can cause an agent to carry out higher-risk actions by default that are unrelated to simply generating video content.
The skill directs scraping third-party websites and downloading assets without clearly warning users that external requests will be made and third-party content will be ingested. This can create privacy, legal, and data-handling risks, especially when URLs or assets are sensitive or proprietary.
Instructing the agent to expose the Remotion dev server through a public Cloudflare tunnel by default creates an unnecessary external attack surface. A development server may reveal source files, local paths, project metadata, or other unintended content, and the public URL can be accessed by anyone who obtains it.
Running npx --yes create-video@latest fetches and executes the latest remote scaffolding package automatically, bypassing review and version stability. That exposes the environment to supply-chain compromise or unexpected behavior introduced in newer releases.
The mandated use of thum.io sends the target URL and requests a rendered snapshot from a third-party service, which may disclose browsing targets or proprietary pages. Without a warning, users may unknowingly transmit sensitive URLs or page content outside their environment.
The script invokes npx --yes create-video@latest, which fetches and executes the latest published package version at runtime rather than a pinned, reviewed version. This creates a supply-chain risk: if the upstream package or one of its dependencies is compromised, arbitrary code may run on the host as soon as the helper script is used.
The script uses npx remotion render, which may resolve and execute whatever remotion package is available through local or remote package resolution. If no vetted local dependency is present, this can result in unpinned code execution from the npm ecosystem, exposing the environment to supply-chain compromise.
The npx remotion preview invocation has the same unpinned execution risk: npx can run a package version that is not explicitly fixed in this script. In a developer workflow script, that means opening the preview path could trigger arbitrary attacker-controlled package code if the dependency source is compromised or unexpectedly resolved.
The npx remotion studio command also relies on unpinned package resolution and can execute non-deterministic code. Because this launches an interactive web interface, developers may run it frequently, increasing exposure to a compromised upstream package or malicious dependency update.
The file advertises itself as a brand data extraction tool even though the skill is described as video-production-only, creating a capability mismatch that can hide unexpected behavior from reviewers and users. This is dangerous in agent systems because undocumented functionality undermines trust boundaries and may enable data collection features to be smuggled into a skill under a less sensitive label.
The script performs live website scraping using a stealth fetcher, which is outside the stated Remotion video-generation scope and materially expands the skill's capability surface. In an agent context, hidden or undocumented scraping can lead to unexpected collection of third-party content and metadata, and makes the skill more dangerous because users invoking a video tool may not expect web reconnaissance or content harvesting.
No suspicious patterns detected.