Back to skill

Security audit

U2-tts

Security checks for vulnerabilities and agentic risk

Overview

This TTS skill mostly matches its stated purpose, but it exposes shared API credentials and grants/uses broader execution and network authority than the task needs.

Install only after replacing the published UniSound credentials with your own, removing or tightly validating the custom --url option, redacting signed URLs from logs, and narrowing agent permissions to the exact TTS command. Use a virtual environment with pinned dependencies and avoid sending sensitive text to the service.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:71
Finding

Hardcoded Shared UniSound API Credentials

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/tts.py:299
Finding

User-Controlled WebSocket Destination Enables Sensitive Data Redirection

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/tts.py:174
Finding

Authentication-Bearing WebSocket URL Is Written to Logs

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:4
Finding

Unpinned and Unnecessary Third-Party Dependencies Expand Supply-Chain Risk

Content
View full analysis
=0.56.0 # Optional: For async operations gevent>=1.4.0 # Dependencies (auto-installed with gevent) greenlet>=0.4.15 cffi>=1.12.3 pycparser>=2.19 six>=1.12.0 ``` The documentation separately instructs: ```bash pip install websocket-client ``` ### Technical Analysis Every dependency uses an open-ended minimum version rather than an audited exact version. No lock file or package hash is provided. A new release satisfying these constraints can therefore be selected without any source change or review. Package installation can execute build backends and native build operations. At runtime, imported packages execute with the same privileges as the TTS process. The requirements also include optional packages that are not used by the reviewed script, unnecessarily increasing the number of packages and transitive components that must be trusted. No specific dependency in the supplied project was proven malicious. The confirmed defect is the absence of reproducible version and integrity controls, which increases exposure to a future compromised, incompatible, or unexpectedly changed release. ### Attack Path 1. A user follows the installation instructions or installs `requirements.txt`. 2. The package resolver selects the newest releases satisfying the open-ended constraints. 3. A selected package or transitive dependency has changed, is compromised, or contains a newly introduced vulnerability. 4. Installation-time build logic or runtime imports execute affected third-party code under the user's account. 5. That code may access files, environment variables, network resources, and credentials available to the process. ### Impact Assessme ...[truncated 405 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
.claude/settings.local.json:3
Finding

Wildcard Python Permission Enables Arbitrary Command Execution

Content
View full analysis
'`. 4. The command matches the wildcard permission and may execute without additional user confirmation. 5. The Python payload reads accessible files or environment variables, modifies the workspace, makes outbound requests, or starts child processes. ### Impact Assessment Exploitation can provide arbitrary code execution with the operating-system privileges of the Agent process. The attacker may access all files, environment secrets, network destinations, and subprocess capabilities available to that account. It does not inherently provide administrator or root privileges, but it breaks the intended least-privilege boundary and can fully compromise the Agent workspace and user-accessible data. ]]>
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Credential Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

The skill includes concrete AppKey and Secret values and instructs users to place them in a .env file. Publishing usable secrets in documentation is credential exposure: anyone reading the skill can reuse them, abuse the vendor account, and potentially access or submit data through the associated API.

Content

Scanner excerpt · SKILL.md (reported line 259)May include surrounding context.

python scripts/tts.py --text '你好'

text

**Method 2: .env File (Recommended for Development)**

Create a `.env` file in the project root:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 546)May include surrounding context.

md
**使用环境变量**——安全地将凭据存储在环境变量中
- **Never hardcode credentials** - Don't embed production credentials in code
  **切勿硬编码凭据**——不要在代码中嵌入生产凭据
- **Use .env files** - For local development (add to .gitignore)
  **使用 .env 文件**——用于本地开发(添加到 .gitignore)
- **Rotate credentials regularly** - In production environments
  **定期轮换凭据**——在生产环境中

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 547)May include surrounding context.

md
**使用环境变量**——安全地将凭据存储在环境变量中
- **Never hardcode credentials** - Don't embed production credentials in code
  **切勿硬编码凭据**——不要在代码中嵌入生产凭据
- **Use .env files** - For local development (add to .gitignore)
  **使用 .env 文件**——用于本地开发(添加到 .gitignore)
- **Rotate credentials regularly** - In production environments
  **定期轮换凭据**——在生产环境中

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares required environment variables and directs the agent to use credentials, but does not define any explicit tool scope such as permissions or allowed-tools. That omission can let a runtime grant broader-than-necessary access to environment data or execution capabilities, violating least privilege and making credential-bearing operations harder to constrain.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instructions say to ONLY use UniSound TTS, NEVER offer alternatives, and STOP immediately on failure. Combined with the skill description's focus on Chinese Mandarin, this prevents offering language or locale choice to the user and imposes a fixed language/tool path without opt-in.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified with only a lower bound, so builds may resolve to different versions over time. This creates supply-chain and reproducibility risk because a later vulnerable or malicious release could be installed without review.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
# U2-TTS Requirements

# Core dependency
websocket-client>=0.56.0

# Optional: For async operations
gevent>=1.4.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The gevent dependency is unpinned, which means the environment may install an unpredictable version. In this case the risk is more meaningful because gevent has known advisories in some versions, so lack of pinning makes it unclear whether deployments are exposed.

Content

Scanner excerpt · requirements.txt (reported line 7)May include surrounding context.

text
websocket-client>=0.56.0

# Optional: For async operations
gevent>=1.4.0

# Dependencies (auto-installed with gevent)
greenlet>=0.4.15

Unverifiable Dependency: gevent has 2 known advisory(ies) (CVE-2023-41419 (Gevent allows remote attacker to escalate privileges); CVE-2023-41419 (An issue in Gevent before version 23.9.0 allows a remote attacker to escalate pr)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The manifest includes gevent without pinning a version, and advisories exist for some gevent releases. Because this skill performs networked, real-time WebSocket-based processing, an affected gevent version could increase exposure to remotely triggered issues or privilege-related flaws in environments where gevent is installed and used.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
50% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · requirements.txt (reported line 10)May include surrounding context.

text
gevent>=1.4.0

# Dependencies (auto-installed with gevent)
greenlet>=0.4.15
cffi>=1.12.3
pycparser>=2.19
six>=1.12.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
50% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · requirements.txt (reported line 11)May include surrounding context.

text
# Dependencies (auto-installed with gevent)
greenlet>=0.4.15
cffi>=1.12.3
pycparser>=2.19
six>=1.12.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
50% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · requirements.txt (reported line 12)May include surrounding context.

text
# Dependencies (auto-installed with gevent)
greenlet>=0.4.15
cffi>=1.12.3
pycparser>=2.19
six>=1.12.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
50% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · requirements.txt (reported line 13)May include surrounding context.

text
greenlet>=0.4.15
cffi>=1.12.3
pycparser>=2.19
six>=1.12.0

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This code sets a Chinese default input string ('今天天气怎么样?') and targets a Chinese TTS endpoint/voice configuration, which creates a language-specific default behavior. The file does not state that Chinese is required or offer locale/language selection as a policy choice beyond voice selection, so the default appears to force a specific language context without explicit opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The --no-cleanup argument is documented as controlling cleanup of old log files, but the script contains no corresponding log cleanup logic anywhere. This creates an intent/documentation mismatch by claiming behavior that the implementation does not perform.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.