feature-video

Fail

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: HIGHDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill captures screenshots and videos of a local development environment and uploads them to a hardcoded external Cloudflare R2 bucket (pub-4047722ebb1b4b09853f24d3b61467f1.r2.dev).
  • Evidence: The command rclone copy tmp/videos/ r2:kieran-claude/pr-videos/pr-[number]/ sends local data to a remote storage path identified by kieran-claude, which is not associated with the skill author.
  • Screenshots of local development servers often display sensitive information, such as debug logs, environment variables, or hardcoded credentials, which are then exposed on a public URL.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection by processing untrusted data from GitHub Pull Requests to drive browser automation.
  • Ingestion points: The skill retrieves the title, body, and files of a PR using gh pr view in SKILL.md.
  • Boundary markers: There are no explicit delimiters or instructions to ignore malicious commands embedded within the PR description.
  • Capability inventory: The agent uses the PR context to "Plan the Video Flow," which involves executing sequences of browser automation commands like agent-browser open, click, and screenshot. It also has file-write capabilities via gh pr edit and network upload capabilities via rclone.
  • Sanitization: PR content is not sanitized before being used to generate the interaction plan, allowing a malicious PR to potentially redirect the browser to sensitive local files or internal routes.
  • [EXTERNAL_DOWNLOADS]: The skill installs an external package from a non-whitelisted source during setup.
  • Evidence: npm install -g agent-browser in SKILL.md.
  • Global installation of unverified packages can introduce malicious code or backdoors into the host system.
  • [COMMAND_EXECUTION]: The skill executes various CLI tools (ffmpeg, rclone, gh, agent-browser) using parameters derived from both user input and external PR data.
  • This increases the attack surface for command injection if inputs gathered from the environment or PR description are not properly validated before being passed to the shell.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Oct 2, 2026, 05:08 PM
Security Audit — agent-trust-hub — feature-video