Back to skill

Security audit

Audio Transcriber Pro

Security checks for vulnerabilities and agentic risk

Overview

The skill does useful audio transcription work, but users should review it because it can send full transcripts to external AI tools and install unpinned packages despite local-processing claims.

Install only if you are comfortable with transcript text potentially being sent to Claude or GitHub Copilot when summary mode runs. For confidential audio, use transcript-only/local mode, avoid installing unpinned packages into a shared Python environment, and review the installer before running it.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

other

Warning
Location
scripts/transcribe.py:275
Finding

Complete transcripts may be transmitted to external LLM services without explicit data-transfer consent

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/transcribe.py:14
Finding

Runtime execution silently installs and imports unpinned Python packages

Content
View full analysis
Remediation
View remediation
--hash=sha256: tqdm== --hash=sha256: ``` 4. Install dependencies only inside a dedicated virtual environment. 5. Require an explicit installation step and show users exactly which packages and versions will be installed. 6. Pin and review transitive dependencies through a lock-generation process. 7. Configure pip to require hashes where practical. 8. If installation fails, stop with a clear error instead of immediately attempting an import after `check=False`. 9. Document the package index and mirror trust assumptions. ]]>

T08 · Insecure Dependencies

Warning
Location
scripts/install-requirements.sh:69
Finding

Dependency installer bypasses managed-environment protections and uses unpinned packages

Content
View full analysis
/dev/null; then echo -e "${GREEN}✅ Faster-Whisper installed successfully${NC}" elif python3 -m pip install --user --break-system-packages faster-whisper --quiet 2>/dev/null; then echo -e "${GREEN}✅ Faster-Whisper installed successfully (user mode)${NC}" else echo -e "${YELLOW}⚠️ Faster-Whisper installation failed, trying Whisper...${NC}" if python3 -m pip install openai-whisper --quiet 2>/dev/null; then echo -e "${GREEN}✅ Whisper installed successfully${NC}" elif python3 -m pip install --user --break-system-packages openai-whisper --quiet 2>/dev/null; then echo -e "${GREEN}✅ Whisper installed successfully (user mode)${NC}" else echo -e "${RED}❌ Failed to install transcription engine${NC}" echo "" echo -e "${YELLOW}Manual installation options:${NC}" echo " 1. Use --break-system-packages (macOS/Homebrew Python):" echo " python3 -m pip install --user --break-system-packages openai-whisper" echo "" echo " 2. Use virtual environment (recommended):" echo " python3 -m venv ~/whisper-env" echo " source ~/whisper-env/bin/activate" echo " pip install faster-whisper" echo "" echo " 3. Use pipx (isolated):" echo " brew install pipx" echo " pipx install openai-whisper" exit 1 fi fi # Install UI/progress libraries (tqdm, rich) echo "" echo -e "${BLUE}📦 Installing UI libraries (tqdm, rich)...${NC}" if python3 -m pip install tqdm rich --quiet 2>/dev/nu ...[truncated 2623 chars]
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Note
Location
scripts/install-requirements.sh:59
Finding

Installer recommends executing a mutable remote Homebrew script through Bash

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (54)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Claiming 100% local processing, no cloud uploads without clarifying that LLM mode changes the privacy model is especially dangerous in this context because audio transcripts commonly contain sensitive business, legal, medical, or personal information. Users may rely on this statement to process confidential recordings and unknowingly exfiltrate the resulting text to external LLM services.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill invokes external AI CLIs, performs prompt engineering, inspects the shell environment, and may install packages, yet these behaviors are not clearly reflected in the high-level description. Hidden external processing and environment interaction materially affect privacy and attack surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill invokes external AI CLIs, performs prompt engineering, inspects the shell environment, and may install packages, yet these behaviors are not clearly reflected in the high-level description. Hidden external processing and environment interaction materially affect privacy and attack surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill invokes external AI CLIs, performs prompt engineering, inspects the shell environment, and may install packages, yet these behaviors are not clearly reflected in the high-level description. Hidden external processing and environment interaction materially affect privacy and attack surface.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · CHANGELOG.md (reported line 83)May include surrounding context.

md
- Improves simple prompts into structured frameworks

- **Temporary files cleanup** - v1.0.0 left `metadata.json` and `transcription.json` as trash
  - Now automatically removed after processing
  - Clean output directory

- **File overwriting** - v1.0.0 used same filename (e.g., `meeting.md`) every time

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description promotes LLM integration for summaries but omits any warning that transcript contents may be sent to external CLI-backed services. In a transcription tool, transcripts often contain meetings, interviews, or client calls, so failure to disclose external data flow can expose confidential or regulated information.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README claims 100% local Whisper processing, no cloud uploads while also advertising Claude/Copilot CLI integration for summaries. That contradiction can mislead users into sending sensitive transcript contents to third-party services under the false assumption that all processing remains local, creating a privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The README instructs users to install via npx cli-ai-skills@latest, which fetches and executes the latest published package without pinning a specific version. This creates a supply-chain risk: if the upstream package is compromised or a breaking/malicious release is published, users may execute unreviewed code during installation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The FAQ states that no internet is required after initial model download, but the skill also supports optional Claude/Copilot-based summaries that typically require network access and may transmit transcript data externally. This misleading statement can cause users to make incorrect trust and compliance decisions in offline or sensitive environments.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill documents shell execution, environment inspection, dependency installation, and file writes, but declares no explicit tool scope or permission boundary. In an agent setting, this mismatch reduces reviewability and informed consent, increasing the chance the skill is invoked with broader capabilities than users expect.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill claims zero-configuration and no external APIs, but later offers optional summarization via external AI tooling. This inconsistency can cause users to share sensitive transcripts under the false assumption that processing remains fully local.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill forwards transcript content to external LLM tools for summarization without a clear privacy warning or consent language describing that potentially sensitive meeting content may leave the local environment. Transcripts can contain credentials, business secrets, personal data, or regulated information, making undisclosed export a significant privacy and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Several user-visible strings are written in Portuguese, including save confirmations and the prompt-selection flow, while the rest of the skill is in English. This effectively imposes a language/locale on users without opt-in, which violates the language-choice policy for natural-language behavior.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill sends both the full transcript and a user-provided custom prompt to external CLI/LLM tooling without guardrails, redaction, or data minimization. This creates a direct path for sensitive content exfiltration and prompt-mediated misuse, especially because transcripts may contain confidential operational details and the prompt can instruct broad disclosure or transformation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The closing claim that the skill does not depend on external APIs conflicts with earlier instructions to use Claude/GPT APIs or Copilot-backed tooling. Contradictory security-relevant documentation increases the risk of inappropriate use with confidential audio or transcripts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest uses Chinese-only natural language for the display name and description, which indicates the skill is presented in a single language without any stated user choice or opt-in. Under the policy rules, forcing a specific language or locale without offering a choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The top comments frame this as a demonstration of the audio-transcriber skill, whose stated purpose includes intelligent summaries using LLM integration. However, the script only invokes local Whisper-based transcription and later states that summary generation is unavailable without separate AI integration, creating an intent-level contradiction between documentation context and actual behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script automatically writes a Markdown transcript derived from spoken audio to disk, which may contain sensitive personal, business, or regulated information. Because the output file is created without any privacy warning, redaction step, or permission hardening, users may unintentionally persist confidential content in a broadly accessible location.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes a capability to create professional Markdown documentation with intelligent summaries via LLM integration. In contrast, the generated output states that automatic summary generation requires AI integration and instructs the user to review the transcription manually, showing that the implemented behavior falls short of the claimed functionality.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The Faster-Whisper example forces language="pt", which is a natural-language locale choice embedded in the skill documentation. Similar hard-coded Portuguese settings appear elsewhere, but the document does not explain that this is a Brazil/Portuguese-specific skill or offer an opt-in choice, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example sets language_code="pt-BR", enforcing a specific language/region in the documented behavior. Because the file is a general comparison for transcription tools rather than a clearly Brazil-specific skill, this locale restriction is not justified or presented as optional.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/install-requirements.sh (reported line 130)May include surrounding context.

sh
if [[ "$OSTYPE" == "darwin"* ]]; then
            echo "  brew install ffmpeg"
        elif [[ "$OSTYPE" == "linux-gnu"* ]]; then
            echo "  sudo apt install ffmpeg  # Debian/Ubuntu"
            echo "  sudo yum install ffmpeg  # CentOS/RHEL"
        fi
    fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/install-requirements.sh (reported line 131)May include surrounding context.

sh
if [[ "$OSTYPE" == "darwin"* ]]; then
            echo "  brew install ffmpeg"
        elif [[ "$OSTYPE" == "linux-gnu"* ]]; then
            echo "  sudo apt install ffmpeg  # Debian/Ubuntu"
            echo "  sudo yum install ffmpeg  # CentOS/RHEL"
        fi
    fi

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Installing packages at runtime is not necessary for the core business logic and introduces avoidable supply-chain and code-execution risk. Because this happens automatically during normal execution, users may unknowingly run newly downloaded code in their environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script auto-installs packages via pip without prompting the user, causing network access and execution of fetched code as a side effect of running the tool. This violates user expectations and increases both supply-chain and operational risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.