Back to skill

Security audit

streaming-audio-memory

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it handles ambient device audio in a high-impact way without enough privacy, consent, retention, or deletion guidance.

Only install this for devices and environments where you have authority to capture audio and send it to BlueColumn/Groq-backed processing. Before use, confirm consent obligations, retention/deletion behavior, access controls, redaction needs, and whether sensitive or bystander audio may be collected.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill explicitly ingests ambient edge-device audio, sends it to an external service for transcription, entity extraction, intent classification, and persistent storage, but does not warn users that highly sensitive bystander or environmental audio may be transmitted off-device and retained. In contexts like cars, doorbells, wearables, and kiosks, this can expose private conversations, location data, and other regulated or sensitive information without informed consent, increasing legal, privacy, and security risk.

Static analysis

No suspicious patterns detected.