Back to skill

Security audit

Webchat Audio Notifications

Security checks for vulnerabilities and agentic risk

Overview

This is a browser audio-notification helper that stores preferences and optional custom sounds locally, with no evidence of hidden agent control, exfiltration, or destructive behavior.

Install only if you are comfortable adding browser JavaScript to your webchat. Uploaded custom sounds and notification preferences are saved in that browser's localStorage until removed or browser data is cleared. Prefer local/self-hosted sound assets, and do not paste publishing API tokens into shell commands on shared systems.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (29)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 85)May include surrounding context.

Simplest (with settings UI):

html
<!-- Load libraries -->
<script src="./howler.min.js"></script>
<script src="./notification.js"></script>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · docs/EASY_SETUP.md (reported line 14)May include surrounding context.

Copy the files and include the settings panel:

html
<!-- Load libraries -->
<script src="./howler.min.js"></script>
<script src="./notification.js"></script>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · docs/EASY_SETUP.md (reported line 185)May include surrounding context.

Don't like the default panel? Build your own:

html
<!-- Enable/Disable -->
<label>
  <input type="checkbox" id="enable-notif" checked 
         onchange="notifier.setEnabled(this.checked)">

Instruction Override

High
Category
Prompt Injection
Confidence
70% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · README.md (reported line 409)May include surrounding context.

1. Check browser console for errors

javascript
// Enable debug mode
const notifier = new WebchatNotifications({ debug: true });

Instruction Override

High
Category
Prompt Injection
Confidence
70% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · README.md (reported line 479)May include surrounding context.

1. Check browser console for errors

javascript
// Enable debug mode
const notifier = new WebchatNotifications({ debug: true });

Instruction Override

High
Category
Prompt Injection
Confidence
70% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 252)May include surrounding context.

1. Check browser console for errors

javascript
// Enable debug mode
const notifier = new WebchatNotifications({ debug: true });

Instruction Override

High
Category
Prompt Injection
Confidence
70% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 288)May include surrounding context.

1. Check browser console for errors

javascript
// Enable debug mode
const notifier = new WebchatNotifications({ debug: true });

Instruction Override

High
Category
Prompt Injection
Confidence
70% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · docs/EASY_SETUP.md (reported line 235)May include surrounding context.

1. Check browser console for errors

javascript
// Enable debug mode
const notifier = new WebchatNotifications({ debug: true });

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · examples/easy-setup.html (reported line 102)May include surrounding context.

html
<button class="trigger-btn" onclick="triggerNotif()">🔔 Trigger Notification</button>
    </div>
    
    <!-- 
      SETTINGS PANEL - Just include this one line in your webchat!
      All styling and logic is self-contained.
    -->

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · client/settings-panel.html (reported line 1)May include surrounding context.

html
<!-- 
  Webchat Audio Notifications - Settings Panel
  Drop-in component for easy configuration

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · examples/settings-panel.html (reported line 1)May include surrounding context.

html
<!-- 
  Webchat Audio Notifications - Settings Panel
  Drop-in component for easy configuration

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · client/settings-panel.html (reported line 228)May include surrounding context.

html
</div>
  </div>

  <!-- Sound Intensity -->
  <div class="notif-setting-row">
    <label class="notif-label" for="notif-sound">
      Sound Intensity

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · examples/settings-panel.html (reported line 228)May include surrounding context.

html
</div>
  </div>

  <!-- Sound Intensity -->
  <div class="notif-setting-row">
    <label class="notif-label" for="notif-sound">
      Sound Intensity

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manual login example shows passing an API token directly on the command line without warning that command-line arguments may be exposed via shell history, process listings, logs, or screenshots. This creates a realistic risk of credential leakage, which could allow unauthorized access to the user's ClawdHub account or publishing capabilities.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide explicitly states that publishing packages the entire directory and describes what is excluded, but it does not instruct users to review the directory for secrets, test artifacts, local configs, or other unintended files before upload. In a publishing workflow, this omission can lead to accidental disclosure of sensitive material to a public package repository, especially because users may assume the listed exclusions are sufficient protection.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a skill that adds browser audio notifications with 5 intensity levels, implying a fixed set of loudness presets. This UI adds a separate custom sound upload feature, including file selection, upload, and removal flows, which is a materially broader behavior than the stated '5 intensity levels' functionality.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes adding browser audio notifications with intensity levels for a webchat, which implies local playback logic for notification sounds. However, the bundled howler.js code supports loading arbitrary src values and performs XMLHttpRequest network fetches for audio data, introducing a broader remote-media loading capability than the description suggests.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes adding browser audio notifications with 5 intensity levels, implying selection among predefined levels. This file also exposes a custom sound upload feature, allowing user-supplied audio files and a new 'custom' mode, which is materially broader behavior than the stated five-level notification feature.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The UI allows users to upload custom audio but provides no clear notice about persistence, storage scope, or handling of the file after upload. In an agent skill context, undisclosed retention or syncing of user-provided media can create privacy and trust risks, especially if users assume the upload is temporary or local-only.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The troubleshooting section includes a deletion command, and while it mentions undelete is possible, it does not clearly warn that this action removes the published skill and may disrupt availability. Markdown instructions for destructive actions should explicitly disclose impact to the user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents an operation that affects user data by accepting user-uploaded files and storing them persistently in the browser. While it notes 'Storage: Browser localStorage,' it does not clearly warn users in this section that their uploaded audio will remain saved locally across sessions unless explicitly removed or browser data is cleared.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README extensively documents custom sound upload as an available feature, including API methods and usage examples at earlier lines, but the 'Next Steps' checklist still marks 'Custom sound upload support' as not implemented. This is an active contradiction in the file's own documentation rather than a mere omission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file applies to SQP-2, and it describes persistent settings being saved in localStorage without any user-facing warning about local data storage or how to clear it. Although the storage is low risk and the Security section notes 'localStorage only,' that is presented as a technical property rather than a user warning about persistence/privacy behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill description is narrowly framed as adding browser audio notifications with intensity levels when the tab is backgrounded, but this bundled howler.js code can load arbitrary audio sources, including remote URLs via XMLHttpRequest and HTML5 Audio. That is broader than the manifest's stated behavior, even if it may be used as an implementation dependency.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.