ffmpeg

Warn

Audited by Snyk on Jun 14, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.80). The skill specifies and runs a remote Docker image ("docker:linuxserver/ffmpeg:latest" / "linuxserver/ffmpeg:latest") which will be pulled and executed at runtime, meaning remote code is fetched and run as a required dependency.

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.70). The skill instructs the user/agent to run privileged commands (sudo apt-get install docker.io and sudo systemctl start/enable docker) which require elevated privileges and modify host system state, even though most FFmpeg work runs inside a container.

Issues (2)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 14, 2026, 03:41 PM
Issues
2
Security Audit — snyk — ffmpeg