Back to skill

Security audit

Local Whisper

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward local audio transcription helper with a normal dependency-installation caution.

Install it as an unprivileged user, expect a large initial model/dependency download, and consider pinning or reviewing package versions if you need reproducible or tightly controlled installs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:44
Finding

Unpinned Third-Party Dependencies Allow Mutable Supply-Chain Inputs

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:44-49
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code

bash
## Setup

Uses uv-managed venv at `.venv/`. To reinstall:
```bash
cd ~/.clawdbot/skills/local-whisper
uv venv .venv --python 3.12
uv pip install --python .venv/bin/python click openai-whisper torch --index-url https://download.pytorch.org/whl/cpu
text

### Technical Analysis

The documented setup command installs `click`, `openai-whisper`, and `torch` without exact version constraints or cryptographic integrity hashes. Consequently, the dependency resolver may install different package versions each time the setup instructions are executed.

Although the configured package index uses HTTPS and there is no evidence that any named dependency is currently malicious, the installation process trusts mutable third-party releases without a reviewed lockfile. A compromised package release, package-index account, or dependency resolution path could introduce unauthorized code after the Skill itself has been reviewed.

Python packages can execute code during installation or whenever imported at runtime. Therefore, compromise of a resolved dependency could lead to code execution under the account running the installation or transcription utility.

### Attack Path

1. An attacker compromises a maintainer account, package release, package index, or transitive dependency used by one of the unpinned packages.
2. The attacker publishes a malicious version that remains compatible with the unconstrained package names.
3. A user follows the setup instructions in `SKILL.md`.
4. `uv pip install` resolves and downloads the attacker-controlled release because no lockfile, exact version, or expected hash restricts the selected artifact.
5. Malicious package code executes during installation or later when `transcribe.py` imports and uses the affected dependen
...[truncated 734 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to an exact, reviewed version rather than installing unconstrained package names.
  2. Generate and commit a reproducible lockfile that records all transitive dependencies.
  3. Require cryptographic hashes for downloaded artifacts where supported, and fail installation when hashes do not match.
  4. Explicitly configure and document trusted indexes for all packages. Verify that the selected index contains the required packages and does not cause unsafe fallback behavior.
  5. Review dependency updates before changing pins, including release provenance, vulnerability advisories, maintainership changes, and transitive dependency differences.
  6. Install dependencies inside the documented isolated virtual environment as an unprivileged user; do not run the setup command with sudo or administrative privileges.
  7. Consider using a controlled internal package mirror containing only reviewed artifacts.

An example hardened workflow is to compile reviewed exact versions and hashes into a lockfile, then install exclusively from that file with hash verification enabled.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.