Back to skill

Security audit

Video Summarizer(视频摘录+Notion/Obsidian知识库存档)

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated video-summary purpose, but a real command-execution flaw in its output-directory handling makes it require review before use.

Install only after the output-directory injection is fixed. Until then, do not let untrusted text, links, or automation choose the output directory, and use dedicated least-privilege API keys, a dedicated OSS bucket, and non-sensitive videos because transcripts and media artifacts may be sent to configured third-party services.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/video-summarize.sh:466
Finding

Arbitrary Python Code Execution Through Output Directory Interpolation

Content
View full analysis
/dev/null || echo "Unknown") UPLOADER=$($PYTHON -c "import json; print(json.load(open('$OUTPUT_DIR/metadata.json')).get('uploader', 'Unknown'))" 2>/dev/null || echo "Unknown") DURATION=$($PYTHON -c "import json; print(json.load(open('$OUTPUT_DIR/metadata.json')).get('duration_string', 'Unknown'))" 2>/dev/null || echo "Unknown") DURATION_SEC=$($PYTHON -c "import json; print(int(json.load(open('$OUTPUT_DIR/metadata.json')).get('duration', 0)))" 2>/dev/null || echo "0") THUMBNAIL=$($PYTHON -c "import json; print(json.load(open('$OUTPUT_DIR/metadata.json')).get('thumbnail', ''))" 2>/dev/null || echo "") ``` The same unsafe interpolation pattern also appears at lines 917, 1006, and 1075. ### Technical Analysis The second positional command-line argument is accepted as `OUTPUT_DIR`. The `validate_output_dir()` function rejects `..` and a limited set of sensitive system directories, but does not reject quote characters or Python syntax. `OUTPUT_DIR` is subsequently inserted directly into source code supplied to `python -c`. Shell quoting does not make this safe because the shell first expands the variable into the double-quoted command argument, after which Python interprets the resulting string as executable source code. An attacker can include a single quote and Python expression syntax in the output directory. For example, a path shaped like the following can cause a function call to be evaluated while Python constructs the argument to `open()`: ```text /tmp/'+str(__import__('os').system('id'))+'x ``` This changes the effective Python expression and invokes `os.system()` before normal file handling finis ...[truncated 1370 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/upload-to-oss.py:312
Finding

Predictable Shared Temporary File Enables Symlink Overwrite and Cross-Job Interference

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (116)

Tainted flow: 'video_info' from os.getenv (line 436, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

The downloader fetches video_info['url'], which ultimately comes from remote page data, without validating the final download host or content type. If the upstream page is malicious or compromised, the tool can be turned into an SSRF or arbitrary-file download mechanism, causing retrieval of attacker-chosen content into the local filesystem.

Content

Scanner excerpt · scripts/douyin_downloader.py (reported line 181)May include surrounding context.

python
if show_progress:
            print(f"正在下载视频:{video_info['title']}")

        response = requests.get(video_info['url'], headers=HEADERS, stream=True)
        response.raise_for_status()

        # 获取文件大小

Tainted flow: 'HEADERS' from os.getenv (line 33, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/push-to-notion.py (reported line 281)May include surrounding context.

python
def search_database(database_id):
    """查询 Notion Database(Data Source)"""
    url = f"https://api.notion.com/v1/data_sources/{database_id}/query"
    response = requests.post(url, headers=HEADERS, json={})
    if response.status_code == 200:
        return response.json()
    else:

Tainted flow: 'HEADERS' from os.getenv (line 33, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/push-to-notion.py (reported line 307)May include surrounding context.

python
for attempt in range(3):
        try:
            timeout = 30 * (attempt + 1)  # 30s, 60s, 90s
            response = requests.post(url, headers=HEADERS, json=data, timeout=timeout)
            if response.status_code == 200:
                break
            elif response.status_code == 400:

Tainted flow: 'HEADERS' from os.getenv (line 33, credential/environment) → requests.patch (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/push-to-notion.py (reported line 337)May include surrounding context.

python
for attempt in range(3):
        try:
            timeout = 30 * (attempt + 1)  # 30s, 60s, 90s
            response = requests.patch(url, headers=HEADERS, json={"children": blocks}, timeout=timeout)
            if response.status_code == 200:
                return True
            elif response.status_code == 400:

Tainted flow: 'headers' from os.getenv (line 131, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/transcribe-audio.py (reported line 137)May include surrounding context.

python
with open(audio_file, 'rb') as f:
            files = {"file": f}
            data = {"model": "whisper-large-v3", "response_format": "verbose_json"}
            response = requests.post(url, headers=headers, files=files, data=data, timeout=600)
    except requests.exceptions.Timeout:
        return {'success': False, 'error': 'Groq API 超时'}
    except requests.exceptions.ConnectionError as e:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 11)May include surrounding context.

text
venv/
env/
.venv/
.env.local

# 临时文件
*.log

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · CHANGELOG.md (reported line 295)May include surrounding context.

md
1. **Step 1 元数据生成(抖音平台)**
   - ❌ 修复前:heredoc 直接展开 `$TITLE` 等变量,存在命令注入风险
   - ✅ 修复后:使用 Python `json.dump()` 安全生成 JSON(自动转义特殊字符)
   - 攻击场景:视频标题包含 `"; rm -rf ~ #` 等恶意内容时可执行任意命令

2. **save_progress() 函数**
   - ❌ 修复前:heredoc 直接展开 `$VIDEO_URL` 和 `$OUTPUT_DIR`

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · CHANGELOG.md (reported line 295)May include surrounding context.

md
1. **Step 1 元数据生成(抖音平台)**
   - ❌ 修复前:heredoc 直接展开 `$TITLE` 等变量,存在命令注入风险
   - ✅ 修复后:使用 Python `json.dump()` 安全生成 JSON(自动转义特殊字符)
   - 攻击场景:视频标题包含 `"; rm -rf ~ #` 等恶意内容时可执行任意命令

2. **save_progress() 函数**
   - ❌ 修复前:heredoc 直接展开 `$VIDEO_URL` 和 `$OUTPUT_DIR`

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The documented workflow includes downloading full video/audio, extracting subtitles, generating screenshots, uploading media, and retaining logs and intermediate artifacts. In the context of an agent skill, this broad collection and persistence of user-requested media increases privacy and data-retention risk, especially when coupled with outbound AI analysis and cloud storage.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented workflow includes downloading full video/audio, extracting subtitles, generating screenshots, uploading media, and retaining logs and intermediate artifacts. In the context of an agent skill, this broad collection and persistence of user-requested media increases privacy and data-retention risk, especially when coupled with outbound AI analysis and cloud storage.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented workflow includes downloading full video/audio, extracting subtitles, generating screenshots, uploading media, and retaining logs and intermediate artifacts. In the context of an agent skill, this broad collection and persistence of user-requested media increases privacy and data-retention risk, especially when coupled with outbound AI analysis and cloud storage.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented workflow includes downloading full video/audio, extracting subtitles, generating screenshots, uploading media, and retaining logs and intermediate artifacts. In the context of an agent skill, this broad collection and persistence of user-requested media increases privacy and data-retention risk, especially when coupled with outbound AI analysis and cloud storage.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented workflow includes downloading full video/audio, extracting subtitles, generating screenshots, uploading media, and retaining logs and intermediate artifacts. In the context of an agent skill, this broad collection and persistence of user-requested media increases privacy and data-retention risk, especially when coupled with outbound AI analysis and cloud storage.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented workflow includes downloading full video/audio, extracting subtitles, generating screenshots, uploading media, and retaining logs and intermediate artifacts. In the context of an agent skill, this broad collection and persistence of user-requested media increases privacy and data-retention risk, especially when coupled with outbound AI analysis and cloud storage.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The documented workflow includes downloading full video/audio, extracting subtitles, generating screenshots, uploading media, and retaining logs and intermediate artifacts. In the context of an agent skill, this broad collection and persistence of user-requested media increases privacy and data-retention risk, especially when coupled with outbound AI analysis and cloud storage.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documented workflow includes downloading full video/audio, extracting subtitles, generating screenshots, uploading media, and retaining logs and intermediate artifacts. In the context of an agent skill, this broad collection and persistence of user-requested media increases privacy and data-retention risk, especially when coupled with outbound AI analysis and cloud storage.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documented workflow includes downloading full video/audio, extracting subtitles, generating screenshots, uploading media, and retaining logs and intermediate artifacts. In the context of an agent skill, this broad collection and persistence of user-requested media increases privacy and data-retention risk, especially when coupled with outbound AI analysis and cloud storage.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documented workflow includes downloading full video/audio, extracting subtitles, generating screenshots, uploading media, and retaining logs and intermediate artifacts. In the context of an agent skill, this broad collection and persistence of user-requested media increases privacy and data-retention risk, especially when coupled with outbound AI analysis and cloud storage.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documented workflow includes downloading full video/audio, extracting subtitles, generating screenshots, uploading media, and retaining logs and intermediate artifacts. In the context of an agent skill, this broad collection and persistence of user-requested media increases privacy and data-retention risk, especially when coupled with outbound AI analysis and cloud storage.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

md
| 编排层 | Bash (`video-summarize.sh`) |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 173)May include surrounding context.

md
| 编排层 | Bash (`video-summarize.sh`) |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 182)May include surrounding context.

md
config.py - video-summarizer 统一配置(Python 端)
所有脚本 import config 即可获取环境变量和路径。

加载链:$AGENT_HOME/.env → $HERMES_HOME/.env → ~/.hermes/.env → ~/.openclaw/.env
"""

import os

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 275)May include surrounding context.

md
config.py - video-summarizer 统一配置(Python 端)
所有脚本 import config 即可获取环境变量和路径。

加载链:$AGENT_HOME/.env → $HERMES_HOME/.env → ~/.hermes/.env → ~/.openclaw/.env
"""

import os

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/check-config.sh (reported line 79)May include surrounding context.

sh
config.py - video-summarizer 统一配置(Python 端)
所有脚本 import config 即可获取环境变量和路径。

加载链:$AGENT_HOME/.env → $HERMES_HOME/.env → ~/.hermes/.env → ~/.openclaw/.env
"""

import os

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/check-config.sh (reported line 120)May include surrounding context.

sh
config.py - video-summarizer 统一配置(Python 端)
所有脚本 import config 即可获取环境变量和路径。

加载链:$AGENT_HOME/.env → $HERMES_HOME/.env → ~/.hermes/.env → ~/.openclaw/.env
"""

import os

Static analysis

No suspicious patterns detected.