Back to skill

Security audit

video-watermark-anti-theft

Security checks for vulnerabilities and agentic risk

Overview

This is a static video watermarking and anti-theft guidance skill with no executable or privileged behavior, though its activation keywords are broad.

Before installing, consider that the skill may activate on broad video- or theft-related prompts and its governance/legal references should be independently verified. It does not appear to run code, access private data, or make changes on its own.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keywords are extremely generic ('video', 'anti', 'theft') and can cause this skill to activate for many unrelated prompts. Over-broad activation increases the chance of incorrect routing, policy bypass through unintended skill selection, or disclosure of skill-specific behavior in contexts where it was not requested.

Static analysis

No suspicious patterns detected.