Back to skill

Security audit

Speech To Text With Speakers

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent AgentPMT transcription integration; it sends audio to remote services as part of its stated purpose, with some privacy and supply-chain considerations users should understand.

Install only if you are comfortable sending the chosen audio or public URL to AgentPMT and its transcription providers, and avoid confidential or regulated recordings unless your organization permits that processing. Prefer the OpenClaw install route or verify/pin any npx-based setup dependencies before running them.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:225
Finding

Unpinned Remote Dependencies Executed Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 225-226
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

Vulnerable Code

bash
npx skills add AgentPMT/agent-skills --skill what-is-agentpmt
npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup

Technical Analysis

The setup instructions direct users to invoke a remotely resolved npx package and install skills from an external source without pinning an exact package version, immutable repository commit, or integrity hash. Consequently, the dependencies executed or installed when a user follows these instructions may differ from those available when this Skill was audited.

This is a supply-chain risk rather than evidence that the current upstream dependencies are malicious. Exploitation requires compromise of the relevant package, publisher account, distribution channel, or mutable upstream content. The commands are documented setup steps and are not automatically executed by the audited files.

Attack Path

  1. An attacker compromises the package publisher, registry entry, source repository, or another mutable component in the dependency chain.
  2. The attacker publishes a malicious version or modifies the remotely retrieved Skill content.
  3. A user follows the documented setup instructions and runs one of the unpinned npx commands.
  4. npx resolves and executes the currently available package rather than an immutable, previously reviewed version.
  5. The compromised installer or installed Skill executes attacker-controlled behavior under the invoking user's permissions.

Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the user running npx. Depending on that user's environment and permissions, this could expose accessible files, credentials, API tokens, agent configuration, or network resources and could modify locally wri ...[truncated 198 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the npx package to an exact, reviewed version instead of relying on mutable resolution.
  • Pin installed Skill content to an immutable repository commit or signed release.
  • Publish and verify cryptographic integrity hashes or signatures before installation.
  • Use a locked dependency manifest where supported and review all transitive dependencies.
  • Prefer downloading and inspecting the package before execution rather than allowing retrieval and execution in one step.
  • Document the expected registry, publisher identity, source repository, version, and checksum so users can validate provenance.
  • Run installation with the least-privileged account available and avoid administrator or root execution.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (18)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill prominently describes transcription capabilities but does not clearly warn that audio content, transcript text, and possibly metadata will be transmitted to external processing providers. In this context, the omission matters because users may supply meetings, interviews, or call recordings containing sensitive personal, corporate, or regulated information without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file states that if language_code is omitted, the tool defaults to 'en-US'. This imposes a specific language/locale behavior without indicating user choice, opt-in, or a justified region-specific constraint, which is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The activation keywords are broad and align with common transcription requests, which can cause the skill to trigger in more situations than a user may expect. Because this skill sends audio or URLs to a remote third-party transcription service, overbroad activation increases the chance of unintended external disclosure of sensitive meeting, interview, or voice data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

This skill is explicitly designed to send user-supplied audio or a public URL to AgentPMT-hosted remote infrastructure and downstream transcription providers, which constitutes external transmission of potentially sensitive content. In a speech-to-text context, the data may include meetings, interviews, names, and other confidential spoken information, so the transmission is security-relevant even if it is core to the product's function.

Content

Scanner excerpt · SKILL.md (reported line 276)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/speech-to-text-with-speakers
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

The REST invoke endpoint confirms that use of the skill sends content and task data to an external service boundary. Because the tool processes recordings and returns transcripts and artifacts, this transmission can expose sensitive speech content if invoked without explicit user awareness or organizational approval.

Content

Scanner excerpt · SKILL.md (reported line 277)May include surrounding context.

md
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/speech-to-text-with-speakers
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The schema documents that audio can be submitted by file ID or public URL and that completed tasks include inline outputs plus stored artifacts, but it does not warn users that their audio and transcript data are sent to an external transcription service and may be retained as artifacts. This creates a real privacy and data-handling risk, especially for sensitive meetings, voice memos, or regulated content, because users may disclose confidential audio without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file states that language_code defaults to en-US when omitted, which imposes a specific locale choice rather than requiring the user to select one. Under the locale-policy rule, forcing a language/locale without user opt-in is a natural-language policy violation unless clearly justified, and no such justification appears here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The public_url parameter causes the service to fetch audio from a user-supplied remote URL, but the schema does not warn about that network retrieval behavior. This matters because users may unintentionally direct the external service to access third-party or sensitive hosted content, creating privacy, provenance, and remote-fetch risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This action repeats the statement that language_code defaults to en-US if omitted, again enforcing a specific locale by default. The file does not offer a language choice flow or explain why an English default is justified for this action.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The standard action also documents that omitted language_code values default to en-US, which is a forced locale choice. No user opt-in or region-specific justification is provided in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Documenting that language_code defaults to en-US without warning means omitted language selection can silently force English transcription. This can reduce accuracy, mishandle non-English audio, and cause unintended processing assumptions, which is a real safety and usability issue, though generally lower severity than direct data exposure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.