Back to skill

Security audit

Call-Transcript-Todo

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but its dependency installation can modify the active Python environment in an overbroad way.

Review before installing. Use it in an isolated environment or virtualenv, pin and verify dependencies if possible, and only provide Feishu credentials if you want documents created there. Expect the default transcription and output workflow to be Chinese-oriented.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:37
Finding

Unpinned Dependency Installation with System Package Protection Bypass

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 37-39
Vulnerability Type: Unpinned third-party package installation from a mutable package index
Risk Level: Medium

Vulnerable Code

bash
pip install faster-whisper --break-system-packages 2>/dev/null || pip install faster-whisper

The dependency is also declared without a version constraint at line 18:

yaml
- faster-whisper (pip install faster-whisper)

Technical Analysis

The skill instructs the agent to install faster-whisper without pinning an exact reviewed version or verifying package integrity with cryptographic hashes. Consequently, the code installed during each invocation depends on the mutable state of the configured Python package index and its dependency resolution graph.

The --break-system-packages option bypasses protections intended to prevent pip from modifying a system-managed Python environment. Redirecting standard error to /dev/null also conceals warnings and diagnostic information that could reveal repository, dependency-resolution, or environment-integrity problems.

This installation process creates a supply-chain execution boundary: a compromised package release, compromised transitive dependency, maliciously configured package index, or future unsafe release could introduce attacker-controlled code. Installation artifacts and imported package code execute with the same operating-system privileges as the agent process.

Attack Path

  1. An attacker compromises a relevant package release, one of its transitive dependencies, or the Python package index configured in the execution environment.
  2. A user invokes the skill in an environment where faster-whisper is not already installed.
  3. The agent executes the documented unpinned pip install command.
  4. Pip resolves and downloads the currently available package and dependency versions without validating them against approved hashes.
  5. Malicio ...[truncated 1084 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin faster-whisper and every transitive dependency to reviewed, exact versions.
  2. Generate a lock file containing cryptographic hashes and install with hash verification, such as pip install --require-hashes -r requirements.txt.
  3. Install dependencies in a dedicated virtual environment or immutable container rather than using --break-system-packages.
  4. Remove the fallback command that modifies the active environment without isolation.
  5. Do not suppress pip error output; retain installation diagnostics for auditing and incident investigation.
  6. Use an approved internal package mirror or explicitly trusted index with repository authentication and transport verification.
  7. Perform dependency vulnerability and provenance scanning before updating the pinned package set.
  8. Run transcription under a least-privileged account without access to unrelated credentials or sensitive files.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The transcription example hard-codes language='zh', and the surrounding instructions and output templates are entirely Chinese-oriented. This creates a language/locale policy issue because the skill does not offer opt-in or fallback behavior for users who want another language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.