Back to skill

Security audit

Global Compliance

Security checks for vulnerabilities and agentic risk

Overview

This package claims to be a compliance skill, but its English and Chinese skill files install and run an unrelated video generator, creating review-boundary, data-handling, and command-execution risk.

Do not install this package as-is. It should be split or republished so all language files describe the same skill, with pinned dependencies, explicit confirmation before running commands or sending content to external APIs, and safe argument handling for user-provided text.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL-EN.md:25
Finding

Unpinned External Code Installation and Execution

Content
View full analysis
Remediation
View remediation
``` 3. Publish and enforce a lockfile, using deterministic installation such as `npm ci`. 4. Verify release signatures, provenance, and integrity checksums before installation. 5. Audit direct and transitive dependencies and enable automated dependency scanning. 6. Avoid package lifecycle scripts where they are unnecessary, for example by initially inspecting dependencies with lifecycle scripts disabled. 7. Vendor the executable source into the audited package or separately audit the exact external revision before execution. 8. Run the installed software with minimum privileges and expose only the environment variables required for the task. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
SKILL-EN.md:101
Finding

Shell Command Injection Through User-Controlled Video Script Interpolation

Content
View full analysis
Remediation
View remediation

other

Warning
Location
SKILL.md:1
Finding

Conflicting Skill Identities and Security-Sensitive Behavior Across Documentation Files

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The audited skill metadata says global-compliance, but the file declares a different skill, video-generator, with unrelated behavior. This identity mismatch is dangerous because it can cause an agent or reviewer to trust, install, or auto-trigger capabilities that were not the ones intended for audit, enabling confused-deputy behavior and bypass of policy review boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The auto-trigger rules are broad enough to fire on ordinary conversation containing generic terms like 'video' or multi-sentence text. In an agent setting, this can cause unsolicited execution paths, repository-dependent shell commands, or networked processing without clear user intent, making the skill more dangerous because it performs costly and externalized actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file claims to belong to a global compliance checker, but its actual content is a video-generation skill with installation and execution instructions for an unrelated external project. This mismatch is dangerous because it can cause an agent or reviewer to trust and invoke capabilities outside the declared security boundary, enabling unauthorized code retrieval and execution under a misleading label.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill states that it uses OpenAI TTS and Whisper but does not clearly warn that user-provided script content and related derived media/transcription data are sent to third-party services. This is risky because users may disclose sensitive content to an agent expecting local processing, and the video-generation context increases the chance of sending proprietary scripts or regulated data off-device.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL-EN.md (reported line 311)May include surrounding context.

md
**DON'T**:
- ❌ Run `npx remotion` to create new projects
- ❌ Assume project is installed without checking
- ❌ Ignore error messages
- ❌ Use hardcoded absolute paths (except `~` paths)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill instructions and operational guidance are presented entirely in Chinese, while the file does not state that the skill is region-specific or offer users an opt-in language choice. This can violate language/locale policy when a skill effectively forces one language for usage and guidance without justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The auto-trigger rules are broad enough to activate on ordinary mentions of videos, scripts, TTS, or Remotion, even when the user did not ask to run this pipeline. In an agent setting, that can lead to unintended command execution, cloning repositories, dependency installation, API usage, and data being sent to external services without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The examples state that generic prompts 'must use this skill,' which pressures the agent to invoke it without adequate disambiguation or consent. This increases the chance of overreach and unintended side effects, especially because the skill includes shell commands, external repository cloning, and API-dependent processing.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill declares AUTO-TRIGGER behavior for broad categories such as legal/regulatory questions, document checking, document generation, and risk assessment. This can cause the agent to invoke the skill in situations where the user did not explicitly request it, potentially exposing sensitive company or policy data to an external CLI/package and producing compliance-style outputs that may be overtrusted.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The keyword trigger list includes generic terms like 'compliance' and 'privacy policy', plus multilingual equivalents, which are common in ordinary conversation. In a high-sensitivity domain handling legal, privacy, and security documents, such generic matching increases the chance of accidental invocation and unintended processing of sensitive content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.