Back to skill

Security audit

Hume EVI + LangGraph Integration

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned, but it includes unsafe guidance for handling voice-call data and API credentials that users should review before installing.

Review this skill before installing or following its examples. Use it only with explicit caller/user consent, documented third-party sharing, retention limits, and protected logs. Do not place reusable Hume API keys in redirect URLs or raw logs; prefer short-lived scoped tokens or a backend-mediated flow, and log only redacted schema metadata when debugging.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:46
Finding

API Credential Embedded in TwiML Redirect URL

Content
View full analysis
Connecting now. https://api.hume.ai/v0/evi/twilio?config_id={config_id}&api_key={api_key} ''' ``` ### Technical Analysis The example places the Hume API key directly in the query string of a redirect URL. Although sending credentials to the declared Hume service supports the Skill's intended voice-integration functionality, placing a reusable secret in a URL unnecessarily expands its exposure. URLs may be captured by application logs, Twilio or Hume request logs, reverse proxies, observability platforms, exception reports, debugging output, and tracing systems. Access controls and retention policies for these systems are frequently less restrictive than controls applied to dedicated secret stores. This is an insecure credential-handling pattern rather than evidence of intentional exfiltration. The destination is consistent with the Skill's declared functionality, but exposing a long-lived API key through a query parameter exceeds minimum safe privilege and data-exposure practices. ### Attack Path 1. A developer implements the documented TwiML redirect using a reusable Hume API key. 2. Twilio, an application proxy, or an observability component records the complete redirect URL. 3. An attacker or unauthorized operator gains read access to those logs, traces, or error reports. 4. The attacker extracts the `api_key` query parameter. 5. The attacker submits unauthorized requests to Hume endpoints accepted by that credential. 6. The credential remains usable until it expires or is explicitly revoked. ### Impact Assessment Successful exploitation may permit unauthorized consumption of the victim's Hume account resources and ...[truncated 456 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/bug-prevention.md:15
Finding

Raw Logging Guidance May Expose Transcripts, Identifiers, and Emotion Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly describes transcript fetching and emotion extraction from voice calls, which involves highly sensitive content and inferred affective data. Omitting any user-facing warning, consent, retention, or privacy guidance creates a real privacy and compliance risk because downstream implementers may deploy surveillance-style processing without notifying callers.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

"event_messages": {"on_new_chat": {"enabled": True, "text": first_message}}, "webhooks": [{"events": ["chat_ended"], "url": webhook_url}], } resp = httpx.post("https://api.hume.ai/v0/evi/configs", json=request_body, headers=headers)

text

### 3. TwiML Redirect (not Stream)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

"event_messages": {"on_new_chat": {"enabled": True, "text": first_message}}, "webhooks": [{"events": ["chat_ended"], "url": webhook_url}], } resp = httpx.post("https://api.hume.ai/v0/evi/configs", json=request_body, headers=headers)

text

### 3. TwiML Redirect (not Stream)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

"event_messages": {"on_new_chat": {"enabled": True, "text": first_message}}, "webhooks": [{"events": ["chat_ended"], "url": webhook_url}], } resp = httpx.post("https://api.hume.ai/v0/evi/configs", json=request_body, headers=headers)

text

### 3. TwiML Redirect (not Stream)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

"event_messages": {"on_new_chat": {"enabled": True, "text": first_message}}, "webhooks": [{"events": ["chat_ended"], "url": webhook_url}], } resp = httpx.post("https://api.hume.ai/v0/evi/configs", json=request_body, headers=headers)

text

### 3. TwiML Redirect (not Stream)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The integration guidance sends call/session data to Hume and Twilio via webhooks and API calls but does not warn that user data leaves the local system and is processed by third parties. In a voice-agent context, that omission is materially dangerous because implementers may unknowingly expose call metadata, transcripts, webhook payloads, and possibly credentials to external vendors without appropriate disclosure or vendor risk review.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The TwiML example places api_key directly in the redirect URL query string, which risks credential exposure through logs, monitoring systems, browser/history equivalents, intermediary services, and accidental disclosure in debugging output. In telephony/webhook environments, URL query parameters are especially likely to be captured, making this a concrete secret-leak vulnerability.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.