other
- Location
scripts/transcribe.py:275- Finding
Complete transcripts may be transmitted to external LLM services without explicit data-transfer consent
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill does useful audio transcription work, but users should review it because it can send full transcripts to external AI tools and install unpinned packages despite local-processing claims.
Install only if you are comfortable with transcript text potentially being sent to Claude or GitHub Copilot when summary mode runs. For confidential audio, use transcript-only/local mode, avoid installing unpinned packages into a shared Python environment, and review the installer before running it.
scripts/transcribe.py:275Complete transcripts may be transmitted to external LLM services without explicit data-transfer consent
scripts/transcribe.py:14Runtime execution silently installs and imports unpinned Python packages
scripts/install-requirements.sh:69Dependency installer bypasses managed-environment protections and uses unpinned packages
scripts/install-requirements.sh:59Installer recommends executing a mutable remote Homebrew script through Bash
Claiming 100% local processing, no cloud uploads without clarifying that LLM mode changes the privacy model is especially dangerous in this context because audio transcripts commonly contain sensitive business, legal, medical, or personal information. Users may rely on this statement to process confidential recordings and unknowingly exfiltrate the resulting text to external LLM services.
The skill invokes external AI CLIs, performs prompt engineering, inspects the shell environment, and may install packages, yet these behaviors are not clearly reflected in the high-level description. Hidden external processing and environment interaction materially affect privacy and attack surface.
The skill invokes external AI CLIs, performs prompt engineering, inspects the shell environment, and may install packages, yet these behaviors are not clearly reflected in the high-level description. Hidden external processing and environment interaction materially affect privacy and attack surface.
The skill invokes external AI CLIs, performs prompt engineering, inspects the shell environment, and may install packages, yet these behaviors are not clearly reflected in the high-level description. Hidden external processing and environment interaction materially affect privacy and attack surface.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
- Improves simple prompts into structured frameworks
- **Temporary files cleanup** - v1.0.0 left `metadata.json` and `transcription.json` as trash
- Now automatically removed after processing
- Clean output directory
- **File overwriting** - v1.0.0 used same filename (e.g., `meeting.md`) every time
The skill description promotes LLM integration for summaries but omits any warning that transcript contents may be sent to external CLI-backed services. In a transcription tool, transcripts often contain meetings, interviews, or client calls, so failure to disclose external data flow can expose confidential or regulated information.
The README claims 100% local Whisper processing, no cloud uploads while also advertising Claude/Copilot CLI integration for summaries. That contradiction can mislead users into sending sensitive transcript contents to third-party services under the false assumption that all processing remains local, creating a privacy and data-handling risk.
The README instructs users to install via npx cli-ai-skills@latest, which fetches and executes the latest published package without pinning a specific version. This creates a supply-chain risk: if the upstream package is compromised or a breaking/malicious release is published, users may execute unreviewed code during installation.
The FAQ states that no internet is required after initial model download, but the skill also supports optional Claude/Copilot-based summaries that typically require network access and may transmit transcript data externally. This misleading statement can cause users to make incorrect trust and compliance decisions in offline or sensitive environments.
The skill documents shell execution, environment inspection, dependency installation, and file writes, but declares no explicit tool scope or permission boundary. In an agent setting, this mismatch reduces reviewability and informed consent, increasing the chance the skill is invoked with broader capabilities than users expect.
The skill claims zero-configuration and no external APIs, but later offers optional summarization via external AI tooling. This inconsistency can cause users to share sensitive transcripts under the false assumption that processing remains fully local.
The skill forwards transcript content to external LLM tools for summarization without a clear privacy warning or consent language describing that potentially sensitive meeting content may leave the local environment. Transcripts can contain credentials, business secrets, personal data, or regulated information, making undisclosed export a significant privacy and compliance risk.
Several user-visible strings are written in Portuguese, including save confirmations and the prompt-selection flow, while the rest of the skill is in English. This effectively imposes a language/locale on users without opt-in, which violates the language-choice policy for natural-language behavior.
The skill sends both the full transcript and a user-provided custom prompt to external CLI/LLM tooling without guardrails, redaction, or data minimization. This creates a direct path for sensitive content exfiltration and prompt-mediated misuse, especially because transcripts may contain confidential operational details and the prompt can instruct broad disclosure or transformation.
The closing claim that the skill does not depend on external APIs conflicts with earlier instructions to use Claude/GPT APIs or Copilot-backed tooling. Contradictory security-relevant documentation increases the risk of inappropriate use with confidential audio or transcripts.
The manifest uses Chinese-only natural language for the display name and description, which indicates the skill is presented in a single language without any stated user choice or opt-in. Under the policy rules, forcing a specific language or locale without offering a choice is a natural-language policy violation.
The top comments frame this as a demonstration of the audio-transcriber skill, whose stated purpose includes intelligent summaries using LLM integration. However, the script only invokes local Whisper-based transcription and later states that summary generation is unavailable without separate AI integration, creating an intent-level contradiction between documentation context and actual behavior.
The script automatically writes a Markdown transcript derived from spoken audio to disk, which may contain sensitive personal, business, or regulated information. Because the output file is created without any privacy warning, redaction step, or permission hardening, users may unintentionally persist confidential content in a broadly accessible location.
The manifest describes a capability to create professional Markdown documentation with intelligent summaries via LLM integration. In contrast, the generated output states that automatic summary generation requires AI integration and instructs the user to review the transcription manually, showing that the implemented behavior falls short of the claimed functionality.
The Faster-Whisper example forces language="pt", which is a natural-language locale choice embedded in the skill documentation. Similar hard-coded Portuguese settings appear elsewhere, but the document does not explain that this is a Brazil/Portuguese-specific skill or offer an opt-in choice, which can violate language/locale policy expectations.
The example sets language_code="pt-BR", enforcing a specific language/region in the documented behavior. Because the file is a general comparison for transcription tools rather than a clearly Brazil-specific skill, this locale restriction is not justified or presented as optional.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
if [[ "$OSTYPE" == "darwin"* ]]; then
echo " brew install ffmpeg"
elif [[ "$OSTYPE" == "linux-gnu"* ]]; then
echo " sudo apt install ffmpeg # Debian/Ubuntu"
echo " sudo yum install ffmpeg # CentOS/RHEL"
fi
fi
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
if [[ "$OSTYPE" == "darwin"* ]]; then
echo " brew install ffmpeg"
elif [[ "$OSTYPE" == "linux-gnu"* ]]; then
echo " sudo apt install ffmpeg # Debian/Ubuntu"
echo " sudo yum install ffmpeg # CentOS/RHEL"
fi
fi
Installing packages at runtime is not necessary for the core business logic and introduces avoidable supply-chain and code-execution risk. Because this happens automatically during normal execution, users may unknowingly run newly downloaded code in their environment.
The script auto-installs packages via pip without prompting the user, causing network access and execution of fetched code as a side effect of running the tool. This violates user expectations and increases both supply-chain and operational risk.
No suspicious patterns detected.