T08 · Insecure Dependencies
- Location
SKILL.md:24- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward Chinese text-to-speech helper, but users should understand it installs an external dependency, sends text to edge-tts, and writes generated audio files locally.
Install only if you are comfortable using edge-tts and sending the text you synthesize to that service. Prefer pipx with a reviewed pinned version, use the default ~/.openclaw/media output location, avoid secrets or regulated data in TTS text, and verify message destinations before sending generated audio.
SKILL.md:24Unpinned Third-Party Dependency Installation
scripts/tts.sh:54Caller-Controlled Output Path Allows Arbitrary File Overwrite
代码的核心功能是本地 TTS 文件生成,这与描述中的“使用 edge-tts 生成”部分一致,也确实支持选择不同 voice。但描述把能力扩展到了“发送语音消息到多渠道”,而代码完全没有网络发送、平台集成、Webhook/API 调用等逻辑;此外描述提到“可调节语速音调”,代码只处理文本、voice 和输出路径三个参数,没有任何速率或音调配置。因此描述高于实际实现,存在实质性能力不匹配。
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
️ macOS 的 Homebrew Python 受 PEP 668 限制,禁止直接 pip install。
不要用
pip install --break-system-packages,会污染系统 Python。
Linux(推荐 pipx,或用 --user 安装):
# 方式一:pipx(推荐)
pipx install edge-tts
# 方式二:pip --user(如果 pipx 不可用)
pip install --user edge-tts
# 安装后确保 ~/.local/bin 在 PATH 中
echo 'export PATH="$HOME/.local/bin:$PATH"' >> ~/.bashrc && source ~/.bashrc
Windows(PowerShell):
pip install edge-tts
# 或
pipx install edge-tts
edge-tts --list-voices | head -5
看到语音列表即安装成功。
message 工具发送(asVoice: true,filePath)bash <skill_dir>/scripts/tts.sh "文本内容" [voice] [output_path]
预期输出:
The description says to use the skill whenever the user asks to '发语音、语音回复、TTS、文字转语音、语音播报、语音消息'. Several of these phrases are broad everyday requests, and the file does not provide scope limits, exclusions, or negative examples to clarify when this skill should or should not activate.
The skill does not clearly warn that user-provided text is sent to an external TTS provider, which can expose sensitive content to a third party. In a messaging skill, users may submit confidential notifications, internal announcements, or personal data, so the lack of disclosure meaningfully increases privacy risk.
The usage text, examples, and default voice are all hard-coded for Chinese text and zh-CN voices, which imposes a specific language/locale by default. There is no natural-language indication that other languages are supported, no user choice prompt, and no documented justification that this skill is intentionally region-specific.
The description repeatedly frames the skill as generating '中文语音' and lists only Chinese voices, but it does not explain that the skill is intentionally limited to Chinese or offer the user a language choice. This can be a language/locale policy issue when a skill forces a specific language without explicit opt-in or justification.
前文参数说明在 L083-L086 明确写明第 1 参数是文本、第 2 参数是声音,但 L157 和 L173 的示例却把 voice 放在第 1 参数、文本放在第 2 参数。这会直接误导调用者,属于文档对实际接口意图的主动性矛盾,而非单纯信息缺失。
No suspicious patterns detected.