Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md **Entry script:** `scripts/video_anime_replace.js` (alongside this `SKILL.md`).
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a narrowly scoped WeryAI video-processing helper that discloses its API-key and network use and does not show hidden local file access or persistence.
Install only if you are comfortable sending the provided public video and image URLs to WeryAI and using your WERYAI_API_KEY for potentially paid jobs. Use dry-run first and confirm inputs before submit or wait.
Referenced artifact was not completely inspected
**Entry script:** `scripts/video_anime_replace.js` (alongside this `SKILL.md`).
Referenced artifact was not completely inspected
**Entry script:** `scripts/video_anime_replace.js` (alongside this `SKILL.md`).
Referenced artifact was not completely inspected
**Entry script:** `scripts/video_anime_replace.js` (alongside this `SKILL.md`).
Referenced artifact was not completely inspected
**Entry script:** `scripts/video_anime_replace.js` (alongside this `SKILL.md`).
Referenced artifact was not completely inspected
**Entry script:** `scripts/video_anime_replace.js` (alongside this `SKILL.md`).
Referenced artifact was not completely inspected
**Entry script:** `scripts/video_anime_replace.js` (alongside this `SKILL.md`).
Referenced artifact was not completely inspected
**Entry script:** `scripts/video_anime_replace.js` (alongside this `SKILL.md`).
Referenced artifact was not completely inspected
**Entry script:** `scripts/video_anime_replace.js` (alongside this `SKILL.md`).
Referenced artifact was not completely inspected
**Entry script:** `scripts/video_anime_replace.js` (alongside this `SKILL.md`).
Referenced artifact was not completely inspected
**Entry script:** `scripts/video_anime_replace.js` (alongside this `SKILL.md`).
Referenced artifact was not completely inspected
**Entry script:** `scripts/video_anime_replace.js` (alongside this `SKILL.md`).
The skill invokes a Node.js script that requires both network access and an API key, but the manifest does not declare an explicit tool/permission scope such as allowed-tools or permissions. That omission weakens containment and reviewability: an agent or runtime may grant broader capabilities than reviewers expect, increasing the chance of unintended outbound requests or secret exposure if the packaged script is modified or behaves unexpectedly.
No suspicious patterns detected.