Back to skill

Security audit

MoodCast

Security checks for vulnerabilities and agentic risk

Overview

MoodCast is a coherent ElevenLabs text-to-audio skill, but it uses mutable install paths and can automatically install an unpinned Python package at runtime.

Review this before installing. Use a pinned, trusted install path, install dependencies in a controlled environment, avoid running it with elevated privileges, and do not submit confidential, regulated, or secret text unless you accept ElevenLabs processing it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
scripts/moodcast.py:18
Finding

Automatic Installation of an Unpinned Python Dependency at Runtime

Content
View full analysis

Vulnerability Details

File Location: scripts/moodcast.py:18-24; related dependency declaration at requirements.txt:1
Vulnerability Type: Runtime supply-chain exposure through an unpinned dependency
Risk Level: Medium

Vulnerable Code:

python
try:
    from elevenlabs.client import ElevenLabs
    from elevenlabs import play
except ImportError:
    print("Installing elevenlabs package...")
    subprocess.check_call([sys.executable, "-m", "pip", "install", "elevenlabs", "-q"])
    from elevenlabs.client import ElevenLabs
    from elevenlabs import play

The corresponding dependency declaration is also not pinned to a reviewed release:

text
elevenlabs>=1.0.0

Technical Analysis

The script automatically invokes pip when an import fails. The installation command does not specify an exact package version or verify a package hash. The requirement permits any elevenlabs version equal to or newer than version 1.0.0.

Consequently, running the application can download and execute package installation logic whose contents may have changed since the skill was audited. The selected package index can also be influenced by Python or pip configuration outside this repository. Automatic installation bypasses the normal separation between dependency review, controlled deployment, and application execution.

This is a supply-chain vulnerability rather than evidence that the current ElevenLabs package is malicious. Exploitation requires compromise or manipulation of the dependency source, package release, package-index configuration, or network trust boundary.

Attack Path

  1. The elevenlabs module is absent from the target Python environment, or an import failure is deliberately induced.
  2. An attacker compromises a future compatible package release, manipulates the configured Python package index, or otherwise causes pip to resolve an attacker-controlled distribution.
  3. The us ...[truncated 1178 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove automatic package installation from application runtime.
  2. On import failure, terminate with a clear message instructing the operator to use an approved installation process.
  3. Pin elevenlabs to an exact, reviewed version instead of using elevenlabs>=1.0.0.
  4. Generate and maintain a lock file containing exact transitive dependency versions.
  5. Require package hashes during installation, such as through a hash-locked requirements file and pip install --require-hashes.
  6. Install dependencies in an isolated virtual environment during a controlled build or deployment stage.
  7. Use a trusted internal package mirror or explicitly approved package index.
  8. Add automated dependency vulnerability and integrity scanning to the release process.
  9. Replace the runtime handler with behavior similar to:
python
try:
    from elevenlabs.client import ElevenLabs
    from elevenlabs import play
except ImportError as exc:
    raise SystemExit(
        "The reviewed ElevenLabs dependency is not installed. "
        "Install dependencies from the project's locked requirements file."
    ) from exc

T08 · Insecure Dependencies

Warning
Location
README.md:50
Finding

Recommended npx Command Executes a Mutable Latest Package Release

Content
View full analysis

Vulnerability Details

File Location: README.md:50-51
Vulnerability Type: Unpinned executable dependency in installation documentation
Risk Level: Medium

Vulnerable Documentation:

bash
# Option 2: Install via MoltHub (recommended)
npx molthub@latest install moodcast

Technical Analysis

The recommended installation command directs npx to obtain and execute the package identified by the mutable latest tag. The repository does not provide a fixed package version, package integrity value, or lockfile for this installer.

Unlike merely downloading static content, npx executes the resolved package's CLI code. Package lifecycle behavior and transitive dependencies may also participate in installation. A future release can therefore execute code that was not present during this audit.

This finding does not establish that the current molthub package is malicious. The risk arises from recommending execution of a mutable, remotely distributed package without pinning or integrity verification.

Attack Path

  1. An attacker compromises the molthub package, its publisher account, a future package release, or a relevant transitive dependency.
  2. The compromised release is assigned the npm latest tag.
  3. A user follows the installation instructions in README.md.
  4. npx resolves molthub@latest to the compromised release and downloads it.
  5. npx executes the package's CLI or installation behavior under the user's account.
  6. Attacker-controlled code can act with the invoking user's available permissions before or during MoodCast installation.

Impact Assessment

Successful exploitation can result in arbitrary code execution as the user following the documented installation procedure. Potential access includes:

  • Files and configuration available to the invoking user.
  • Agent or skill directories writable by that user.
  • Environment variables and credentials exposed to th ...[truncated 451 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace molthub@latest with an exact, reviewed package version.
  2. Document the expected package identity, version, and integrity information.
  3. Avoid presenting execution of a mutable npm release as the recommended installation path.
  4. Where supported, use a lockfile and a deterministic installation workflow.
  5. Verify the package provenance and npm publisher controls before updating the documented version.
  6. Review release changes before advancing the pinned installer version.
  7. Advise users not to run the installer with administrator or root privileges.
  8. Prefer an installation mechanism that verifies signed or integrity-protected artifacts before executing them.

A safer documented command should use a specific reviewed version, for example:

bash
npx molthub@REVIEWED_EXACT_VERSION install moodcast

The placeholder must be replaced with an actual audited version and, where tooling permits, supplemented by integrity verification.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (14)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README describes transforming user text with ElevenLabs APIs but does not clearly warn that submitted text and ambient prompts are sent to third-party services. Users may provide sensitive, confidential, or regulated content without realizing it leaves their local environment, creating privacy, compliance, and data-handling risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The README instructs users to run npx molthub@latest install moodcast, which fetches and executes the latest package version at install time. Because it is not pinned to a specific version, users may unknowingly execute changed or compromised code from the package registry, creating a supply-chain risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

This second installation reference again tells users to run npx molthub@latest install moodcast, leaving execution dependent on whatever version is current in the registry. In a skill-installation context, this is especially risky because the command directly affects the local agent environment and could introduce malicious or unstable code.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares shell and environment-variable usage via examples and metadata, but it does not define an explicit tool scope such as permissions or allowed-tools. This can lead to over-broad execution in agent environments, making it easier for the skill to invoke shell commands or access sensitive environment data beyond what users expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description explains audio transformation features but does not clearly warn that submitted text is transmitted to ElevenLabs external APIs for text-to-speech and sound generation. Users may provide sensitive or proprietary text under the assumption processing is local, leading to privacy and confidentiality exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases include broad, natural language expressions such as 'make this sound good' and 'create audio for', which could match ordinary conversation and cause unintended skill activation. In a skill that sends user text to an external API and invokes shell commands, accidental invocation increases the risk of unintentional data disclosure and unexpected actions.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
93% confidence
Finding

The script automatically installs a Python package at runtime via pip, which executes external code and changes the local environment without prior user approval. This creates supply-chain and environment-integrity risk if the package, index, or dependency chain is compromised, and it exceeds the minimum capability needed for a text-to-audio helper.

Content

Scanner excerpt · scripts/moodcast.py (reported line 23)May include surrounding context.

python
from elevenlabs import play
except ImportError:
    print("Installing elevenlabs package...")
    subprocess.check_call([sys.executable, "-m", "pip", "install", "elevenlabs", "-q"])
    from elevenlabs.client import ElevenLabs
    from elevenlabs import play

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Runtime package installation introduces an unnecessary execution capability beyond straightforward API usage and can modify the host system unexpectedly. In a skill context, silently invoking pip increases trust and supply-chain risk because users may not expect the tool to download and execute code from external repositories.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The user's text is sent to a third-party API, but the tool does not provide a clear privacy or data-transfer warning before transmitting potentially sensitive content. In a text-processing skill, this matters because users may assume local handling and unknowingly disclose confidential or regulated information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Ambient prompts are also transmitted to the external ElevenLabs Sound Effects API without an explicit warning, creating the same data-exposure concern for user-provided content. Although prompts may seem less sensitive, they can still contain confidential scenario details or identifying information.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest focuses on generating emotionally expressive audio and ambient soundscapes using ElevenLabs services, but the implementation also executes local binaries such as afplay, mpv, ffplay, and aplay. Launching arbitrary local executables is a broader host-interaction capability than the described generation task and is not explicitly declared in the skill purpose.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/moodcast.py (reported line 226)May include surrounding context.

python
for player in players:
            try:
                if player == "ffplay":
                    subprocess.run([player, "-nodisp", "-autoexit", temp_path], 
                                 check=True, capture_output=True)
                else:
                    subprocess.run([player, temp_path], check=True, capture_output=True)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/moodcast.py (reported line 229)May include surrounding context.

python
subprocess.run([player, "-nodisp", "-autoexit", temp_path], 
                                 check=True, capture_output=True)
                else:
                    subprocess.run([player, temp_path], check=True, capture_output=True)
                break
            except (FileNotFoundError, subprocess.CalledProcessError):
                continue

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified with a lower bound only (elevenlabs>=1.0.0), which allows future major or minor releases to be installed without review. This creates supply-chain and reliability risk because a later upstream release could introduce breaking changes or a malicious/compromised package version that the skill would automatically accept.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
elevenlabs>=1.0.0

Static analysis

No suspicious patterns detected.