Back to skill

Security audit

Kittentts

Security checks for vulnerabilities and agentic risk

Overview

This is a small local text-to-speech skill with disclosed dependency and Telegram integration risks, but no evidence of hidden, destructive, or deceptive behavior.

Install in an isolated virtual environment, verify the KittenTTS release source before installing, consider pinning soundfile and hashes, and avoid sending sensitive text through the Telegram integration unless you intend the generated audio to be transmitted externally.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:6
Finding

Unpinned and Integrity-Unverified Third-Party Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 6
Vulnerability Type: Supply-chain exposure through unverified and unpinned dependencies
Risk Level: Medium

Complete Code Snippet:

bash
pip install https://github.com/KittenML/KittenTTS/releases/download/0.8.1/kittentts-0.8.1-py3-none-any.whl soundfile

Technical Analysis

The installation command downloads and installs a Python wheel directly from an external GitHub release without verifying its cryptographic hash. Although the KittenTTS filename contains a version, the command does not ensure that the downloaded bytes match a reviewed artifact. The soundfile dependency is not version-pinned and has no integrity constraint, so its selected version can vary over time.

Python package installation and subsequent imports may execute third-party code with the privileges of the user running the command. If the GitHub release asset, upstream account, package index, dependency resolution process, or a transitive dependency is compromised, following the documented installation procedure could install attacker-controlled code.

The repository contains only SKILL.md; therefore, the referenced CLI wrapper and dependency behavior could not be inspected. No evidence establishes that the currently referenced packages are malicious. The finding concerns the lack of reproducibility and integrity enforcement in the documented installation process.

Attack Path

  1. An attacker compromises an upstream release asset, package publishing account, package-index distribution channel, or unresolved dependency.
  2. The attacker replaces or publishes a package artifact containing malicious installation or runtime code.
  3. A user follows the installation command in SKILL.md.
  4. pip downloads the artifact without checking it against a trusted hash and resolves the unpinned soundfile package and transitive dependencies.
  5. Attacker-controlled code executes dur ...[truncated 583 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin every direct dependency to an exact reviewed version.
  • Generate and maintain a lock file that fixes transitive dependency versions.
  • Record trusted SHA-256 hashes for all package artifacts and install with hash enforcement, such as pip install --require-hashes -r requirements.txt.
  • Download the KittenTTS wheel through a controlled build or artifact pipeline, verify its provenance and signature where available, and store an approved immutable copy in a trusted registry.
  • Review package metadata, installation hooks, and transitive dependencies before approval.
  • Perform installation and execution in an isolated virtual environment or sandbox with minimal filesystem and network privileges.
  • Include the referenced kittentts_cli.py in the audited project, or provide a verifiable source and immutable revision, so its behavior can be reviewed.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

YARA rule 'agent_skill_remote_bootstrap_execution': Remote script or code download followed by execution/bootstrap installation [agent_skills]

High
Category
YARA Match
Confidence
85% confidence
Finding

The installation instructions tell users to install a wheel directly from a remote GitHub release URL, which bypasses normal package index trust and encourages execution of externally hosted code without integrity verification. If the release asset, repository, or delivery path is compromised, users could install malicious code into their environment.

Content

Scanner excerpt · SKILL.md (reported line 8)May include surrounding context.

KittenTTS Skill

Génère des réponses audio TTS localement avec le modèle KittenTTS.

Installation

bash
pip install https://github.com/KittenML/KittenTTS/releases/download/0.8.1/kittentts-0.8.1-py3-none-any.whl soundfile

Utilisation

python
from kittentts import KittenTTS

# Charger le modèle (nano = plus léger, mini = meilleure qualité)
model = KittenTTS("KittenML/kitten-tts-nano-0.8-int8")

# Générer audio
audio = model.generate("Bonjour Fred !", voice="Bella")

# Sauvegarder
model.generate_to_file("Bonjour Fred !", "output.wav", voice="Luna")

Voix disponibles

  • Luna (défaut)
  • Bella
  • Jasper
  • Luna
  • Bruno
  • Rosie
  • Hugo
  • Kiki
  • Leo

Modèles

| Modèle | Par

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill states that generated audio will be sent automatically over Telegram, but it does not clearly warn users that their text-derived content may be transmitted to a third-party service. This can cause unintended disclosure of sensitive prompts, names, or audio content, especially in agent workflows where users may assume processing is purely local.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The natural-language instructions throughout the skill file are presented only in French, which may amount to forcing a specific language without user opt-in. The file does not indicate that the skill is intentionally region-specific or offer an alternative language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.