Back to skill

Security audit

speaker-local

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward local text-to-speech helper, with disclosed external installation and model-download steps but no hidden behavior or elevated access.

Install only if you trust the kokoro-tts package and its GitHub release assets. Prefer pinning the package version and verifying published checksums for the model files before use, and run it with normal user permissions on files you intend to convert.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:35
Finding

Unpinned Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:35-39
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: Medium

Vulnerable Code

bash
## Install

```bash
uv tool install kokoro-tts
text

### Technical Analysis

The installation command retrieves and installs the current version of the third-party `kokoro-tts` package without pinning an audited version or verifying its integrity. This package supplies the executable behavior of the Skill, but its source and transitive dependencies are not included in the audited project.

Because dependency resolution occurs at installation time, the effective executable payload can change after this Skill has been reviewed. A compromised publisher account, malicious future release, package ownership transfer, or compromised transitive dependency could introduce attacker-controlled code.

Installing the TTS implementation is necessary for the declared functionality, and the command does not request administrative privileges. Nevertheless, allowing an unpinned package to execute with the invoking user's permissions exceeds the minimum supply-chain trust needed when a fixed, reviewed version could be specified.

### Attack Path

1. An attacker compromises the package publisher, distribution account, or a resolved dependency.
2. The attacker publishes a malicious package version that still satisfies the unpinned package name.
3. A user follows the Skill's installation instruction.
4. `uv` retrieves and installs the attacker-controlled release.
5. Malicious installation or runtime behavior executes with the permissions of the invoking user when the package is installed or used.

### Impact Assessment

Successful exploitation could permit arbitrary code execution in the user's security context. Depending on that user's existing permissions, the compromised package could read or modify accessible files, access available credentials or environm
...[truncated 182 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin kokoro-tts to a specific reviewed version rather than resolving the latest available release.
  • Use a lockfile or equivalent mechanism to pin all transitive dependencies.
  • Require hashes for downloaded package artifacts where supported.
  • Document the expected package publisher and canonical source repository.
  • Review the pinned package and its dependency graph before recommending installation.
  • Obtain explicit user approval before installing external executable dependencies.
  • Run the tool with ordinary user permissions and, where practical, inside an isolated environment with only the input and output paths required for TTS.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:40
Finding

Model Assets Downloaded Without Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:40-46
Vulnerability Type: Unverified external model and voice-data downloads
Risk Level: Medium

Vulnerable Code

bash
Model files (`kokoro-v1.0.onnx`, `voices-v1.0.bin`) must be in the working directory. Download once:

```bash
wget https://github.com/nazdridoy/kokoro-tts/releases/download/v1.0.0/kokoro-v1.0.onnx
wget https://github.com/nazdridoy/kokoro-tts/releases/download/v1.0.0/voices-v1.0.bin
text

### Technical Analysis

The Skill instructs users to download an ONNX model and a `.bin` voice-data file from a GitHub release without validating cryptographic checksums or signatures. These assets are directly relevant to local text-to-speech functionality and are fetched from a versioned release under the repository named by the Skill, so the network access is functionally justified.

The identified `.bin` file is documented as voice data, not as a directly launched native executable. The ONNX file is likewise a serialized model. Therefore, the project does not demonstrate direct execution of the flagged file itself. However, both files are externally supplied binary inputs loaded by the TTS implementation and associated parsing libraries. If the release account or assets were compromised or replaced, malicious or corrupted content could be supplied after the Skill review. Such content could alter generated speech, cause denial of service, or potentially exploit a vulnerability in the relevant parser or model runtime.

### Attack Path

1. An attacker compromises the upstream repository, release account, distribution path, or published release assets.
2. The attacker replaces one or both assets with malicious or corrupted binary content.
3. A user executes the documented `wget` commands without checksum or signature verification.
4. The user invokes `kokoro-tts`, which loads and parses the downloaded assets.
5. The modified assets produce attacker-co
...[truncated 845 chars]
Remediation
View remediation

Remediation Suggestions

  • Publish trusted SHA-256 or stronger checksums for both release assets.
  • Add checksum verification commands immediately after downloading and abort on any mismatch.
  • Prefer cryptographically signed release manifests and verify signatures against a documented maintainer key.
  • Store downloads in a dedicated, non-executable data directory rather than the general working directory.
  • Pass explicit validated paths through --model and --voices.
  • Load the assets under ordinary user permissions and isolate the TTS process where practical.
  • Document the exact expected file sizes, release tag, canonical repository, and integrity values.
  • Review and update pinned assets deliberately rather than silently accepting replacements.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This plain-text reference begins with a generic CLI synopsis and usage note but does not define specific activation phrases, boundaries, or negative examples for when the skill should or should not be invoked. For manifest/text-style activation guidance, that ambiguity can make invocation scope overly broad.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.