Back to skill

Security audit

Geode On-device Transcribe & Summary

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a real Geode transcription integration, but its command templates expose user-supplied values to local shell execution risk and its privacy/retention behavior is under-scoped.

Review this skill before installing. It needs access to local audio files and will store copied audio, task metadata, transcripts, and summaries in Geode's shared container. The current manifest should be fixed to use structured, validated command arguments before it handles untrusted paths or task IDs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
skill.json:34
Finding

Command Injection Through Unquoted Tool Parameters

Content
View full analysis
Remediation
View remediation
- --language - ``` Add `--summary` as a separate argument only when requested. Apply the same approach to `--task-status`. 2. **Validate task IDs.** Require `task_id` to match canonical UUID syntax, such as: ```regex ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-5][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}$ ``` 3. **Restrict language values.** Use a schema enumeration containing only language codes supported by `GeodeCLI`, rather than accepting an arbitrary string. 4. **Validate and canonicalize audio paths.** Require an absolute path, resolve symbolic links where appropriate, verify that the target exists and is a regular readable file, and optionally restrict it to the documented App Group inbox. 5. **Use framework-native escaping only as a fallback.** If the platform cannot avoid command strings, apply its documented shell-escaping mechanism independently to every interpolated parameter. Adding literal quotation marks alone is insufficient unless embedded quotes and command substitutions are safely escaped. 6. **Add security tests.** Test spaces, quotation marks, semicolons, command substitutions, pipelines, redirections, newlines, and leading hyphens in all string parameters. Verify that each value reaches `GeodeCLI` as exactly one literal argument and cannot create additional commands or options. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest advertises transcription and summarization as occurring locally, but the body of the skill references login state, quota enforcement, and AI summary/transcription failure modes that imply dependence on a service-backed workflow rather than purely on-device processing. This can mislead users into providing sensitive audio under incorrect privacy assumptions, creating a trust and data-handling risk even if the implementation is otherwise functional.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The instructions direct the agent to copy user audio into a shared App Group container and write transcripts/summaries there, but provide no user-facing disclosure about persistent local copies being created. For sensitive recordings, this increases the chance of unintended retention or later access by other components with access to the same container, especially because the workflow explicitly persists task JSON and outputs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This is a manifest file, so vague-trigger checks apply. The description and tool metadata explain what the skill does, but do not define when it should or should not be invoked, provide explicit trigger phrases, or include exclusion examples, which can lead to unintended activation for generic requests about transcription or summarization.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The natural-language parameter description presents a general language choice, but the default is hard-coded to 'zh'. For a general-purpose transcription skill, forcing a specific language by default can violate language/locale policy unless the user explicitly opts in or the locale restriction is clearly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The agent is instructed to return raw transcriptPath and summaryPath values, which exposes full local filesystem locations and reveals where sensitive artifacts are stored. While lower severity than direct data exfiltration, this unnecessarily discloses host-specific path information and may normalize leaving sensitive outputs in predictable locations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.