feature-video
Fail
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: HIGHDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill captures screenshots and videos of a local development environment and uploads them to a hardcoded external Cloudflare R2 bucket (
pub-4047722ebb1b4b09853f24d3b61467f1.r2.dev). - Evidence: The command
rclone copy tmp/videos/ r2:kieran-claude/pr-videos/pr-[number]/sends local data to a remote storage path identified bykieran-claude, which is not associated with the skill author. - Screenshots of local development servers often display sensitive information, such as debug logs, environment variables, or hardcoded credentials, which are then exposed on a public URL.
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection by processing untrusted data from GitHub Pull Requests to drive browser automation.
- Ingestion points: The skill retrieves the title, body, and files of a PR using
gh pr viewinSKILL.md. - Boundary markers: There are no explicit delimiters or instructions to ignore malicious commands embedded within the PR description.
- Capability inventory: The agent uses the PR context to "Plan the Video Flow," which involves executing sequences of browser automation commands like
agent-browser open,click, andscreenshot. It also has file-write capabilities viagh pr editand network upload capabilities viarclone. - Sanitization: PR content is not sanitized before being used to generate the interaction plan, allowing a malicious PR to potentially redirect the browser to sensitive local files or internal routes.
- [EXTERNAL_DOWNLOADS]: The skill installs an external package from a non-whitelisted source during setup.
- Evidence:
npm install -g agent-browserinSKILL.md. - Global installation of unverified packages can introduce malicious code or backdoors into the host system.
- [COMMAND_EXECUTION]: The skill executes various CLI tools (
ffmpeg,rclone,gh,agent-browser) using parameters derived from both user input and external PR data. - This increases the attack surface for command injection if inputs gathered from the environment or PR description are not properly validated before being passed to the shell.
Recommendations
- AI detected serious security threats
Audit Metadata