Back to skill

Security audit

Jarvis Tts

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small text-to-speech helper whose network and command use match its stated purpose, with privacy and dependency cautions users should understand.

Install this only if you are comfortable sending the text you ask it to speak to Microsoft's TTS service and installing edge-tts from pip. Do not use it to read secrets, credentials, or confidential material aloud, and prefer a pinned dependency in an isolated environment if reproducibility matters.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:75
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:75
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code Snippet:

markdown
**Dependencies:**
- Python 3
- edge-tts (`pip3 install edge-tts`)

Technical Analysis

The documented installation command retrieves the latest available edge-tts release without pinning a reviewed version or verifying an integrity hash. Consequently, the dependency artifact installed by users can change after the Skill has been audited.

This creates a supply-chain exposure: if the upstream package, publisher account, or distribution channel is compromised, a malicious package release could execute installation-time or runtime code with the privileges of the user installing or invoking the Skill. The audit found no evidence that the currently referenced package is malicious; the risk arises from the unsafe, non-reproducible dependency installation procedure.

Attack Path

  1. An attacker compromises the upstream package publisher, package repository, or a future package release.
  2. The attacker publishes a malicious version under the expected edge-tts package name.
  3. A user follows the documented pip3 install edge-tts instruction without a version constraint or hash verification.
  4. The package manager downloads and installs the attacker-controlled release.
  5. Malicious installation-time code, imported module code, or runtime code executes when the package is installed or when python3 -m edge_tts is invoked by scripts/jarvis-tts.py.

Impact Assessment

Exploitation could permit arbitrary code execution with the privileges of the user who installs or runs the dependency. Depending on that user's permissions, the attacker could access user-readable files, alter user-owned data, make network requests, or execute additional local processes. The Skill itself does not request elevated privileges, so the direct scope is ordinaril ...[truncated 105 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin edge-tts to a specifically reviewed version rather than installing the latest release, for example through a version-locked requirements file.
  • Generate and verify cryptographic hashes for all dependency artifacts, such as by using pip install --require-hashes -r requirements.txt.
  • Commit the dependency lock file to the project so installations are reproducible.
  • Install dependencies from the official package index over authenticated TLS and avoid untrusted mirrors or additional package indexes.
  • Review dependency updates before changing the pinned version, including transitive dependency changes.
  • Install the package in an isolated virtual environment under a non-privileged account; do not use administrator or root installation unless strictly required.
  • Consider automated dependency vulnerability and provenance checks as part of release validation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises shell-based execution paths (jarvis-tts.sh, python3, afplay, edge-tts) but does not declare any explicit tool scope or permissions in the skill metadata. This creates a governance and least-privilege gap: an agent may invoke shell capabilities without clear user/developer visibility into what execution is required, increasing the risk of unintended command execution or unsafe integration assumptions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill states that it requires a network connection and uses Microsoft edge-tts, but it does not clearly and prominently warn that user-provided text is transmitted to Microsoft's TTS service. Users may provide sensitive prompts, credentials, personal data, or confidential content under the assumption of local processing, leading to unintended third-party disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language instructions and defaults are entirely Chinese, and the default voice is fixed to zh-CN-YunxiNeural. There is no documented opt-in, language selection guidance, or explanation that the skill is intentionally limited to a Chinese-language context.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/jarvis-tts.py (reported line 20)May include surrounding context.

python
try:
        # 生成语音(等待完成)
        print(f"🔊 生成语音...")
        result = subprocess.run([
            sys.executable, "-m", "edge_tts",
            "--voice", voice,
            "--text", text,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill sends user-provided text to edge_tts, which relies on an external Microsoft-backed service, but the code provides no explicit privacy notice or consent mechanism. If users dictate secrets, personal data, or confidential content, that data may leave the local environment unexpectedly, creating a real privacy and compliance risk.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/jarvis-tts.py (reported line 35)May include surrounding context.

python
print(f"✅ 生成成功,播放中...")
        
        # 播放音频(等待完成)
        subprocess.run(["afplay", tmpfile.name], timeout=120)
        
        print("✅ 播放完成")
        return True

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's natural-language interface is entirely in Chinese, including the description and usage output, which imposes a specific language on users. There is no indication that this skill is region-specific or that users can opt into another language, matching the locale-policy violation criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.