Back to skill

Security audit

Sag Andy27725

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward ElevenLabs text-to-speech skill with disclosed API-key use and a normal but trust-sensitive third-party Homebrew install.

Install this only if you are comfortable trusting the sag Homebrew tap and using an ElevenLabs API key with the CLI. Avoid sending sensitive text for speech generation unless that fits your ElevenLabs usage policy, and change the output path if /tmp/voice-reply.mp3 should not be overwritten.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Third-Party Homebrew Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 13–20
Vulnerability Type: Supply-chain risk from a mutable third-party package source
Risk Level: Medium

Vulnerable Code

yaml
"install":
  [
    {
      "id": "brew",
      "kind": "brew",
      "formula": "steipete/tap/sag",
      "bins": ["sag"],
      "label": "Install sag (brew)",
    },
  ],

Technical Analysis

The skill delegates installation of the sag executable to the third-party Homebrew tap steipete/tap without specifying an immutable version, source commit, cryptographic checksum, or trusted signature. Consequently, the code installed in the future may differ from the dependency that was originally reviewed.

Homebrew formula installation can download artifacts and execute installation logic on the local system. Because this skill also requires ELEVENLABS_API_KEY, a compromised or malicious dependency could attempt to access that credential when subsequently executed. The audit found no evidence that the current package is malicious; the confirmed weakness is the absence of dependency pinning and integrity verification.

Attack Path

  1. An attacker compromises the third-party tap, its maintainer account, release infrastructure, or a referenced binary artifact.
  2. The attacker modifies the formula or replacement artifact while retaining the expected formula and executable names.
  3. A user or agent follows the skill metadata and installs steipete/tap/sag.
  4. Homebrew retrieves and installs the altered dependency.
  5. Malicious installation or runtime code executes with the installing user's privileges.
  6. The altered executable may access files available to that user, misuse the required ElevenLabs credential, or perform unauthorized network operations.

Impact Assessment

Successful exploitation could provide code execution with the privileges of the user performing the installation or invoking ...[truncated 295 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a specific audited release and, where supported, an immutable source commit.
  2. Verify downloaded artifacts with a published cryptographic checksum and preferably a trusted signature.
  3. Document the exact upstream repository, release version, expected digest, and verification procedure.
  4. Review the Homebrew formula and all transitive download locations before approving installation.
  5. Prevent silent upgrades to unreviewed versions and require security review when the pinned version changes.
  6. Run the CLI with least privilege and provide only the environment variables required for the immediate operation.
  7. Rotate the ElevenLabs API key if dependency compromise is suspected, and constrain the key through provider-side quotas or permissions where available.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

Because this is a markdown file, SQP-2 applies to documented behaviors that affect user data or system integrity. The example explicitly creates /tmp/voice-reply.mp3 via -o but does not warn that the skill will write a local file, which is a user-visible side effect.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.