T09 · Insecure Skill Coding Practices
- Location
scripts/cd2flac.py:450- Finding
Source files are deleted even when audio conversion fails
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill mostly does what it says, but it can delete source audio files unsafely and sends music metadata to external lyric services with weak disclosure and an insecure HTTP fallback.
Install only if you are comfortable with it modifying your music files. Run on backed-up copies first, prefer --dry-run and --keep-wav --keep-cue, avoid --delete-rar unless you have verified outputs, and use --lyrics or lyric.py only if you accept sending track metadata to Netease/Kugou, including an insecure HTTP Kugou fallback.
scripts/cd2flac.py:450Source files are deleted even when audio conversion fails
scripts/lyric.py:83Kugou lyric queries and responses use unencrypted HTTP
scripts/lyric.py:20Reusable Netease service token is embedded in source code
The documented purpose centers on archive extraction and audio conversion, but the analyzed behavior reportedly focuses on network lyric lookup and metadata injection while omitting the core advertised conversion workflow. This mismatch is dangerous because reviewers or users may grant trust and permissions based on the stated purpose while the actual behavior performs different operations, including outbound network activity and media metadata modification.
The skill documentation declares no explicit tool scope despite requiring shell execution, file reads/writes, and network access. In an agent environment, missing permissions metadata can cause the skill to run with broader-than-expected capabilities, reducing reviewability and increasing the chance of unsafe execution or abuse.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
## Requirements
- **System packages**: `unrar`, `cuetools`, `shntool`, `flac`
- Install: `sudo apt-get install -y unrar cuetools shntool flac`
## Python dependencies
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
## Requirements
- **System packages**: `unrar`, `cuetools`, `shntool`, `flac`
- Install: `sudo apt-get install -y unrar cuetools shntool flac`
## Python dependencies
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
## Requirements
- **System packages**: `unrar`, `cuetools`, `shntool`, `flac`
- Install: `sudo apt-get install -y unrar cuetools shntool flac`
## Python dependencies
The README advertises deletion of source archives and cleanup of original WAV/CUE files without a prominent warning about irreversible data loss. This creates a safety risk because users may invoke destructive options without understanding that original media or archives could be permanently removed.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
else:
kwargs.update(stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL)
try:
result = subprocess.run(cmd, **kwargs)
except subprocess.TimeoutExpired:
return -1, "", "TIMEOUT"
if capture:
The --recursive help text at L395-L396 states the skill will process subdirectories as separate albums. But in recursive mode, main calls process_album(album_path, None, args) at L432, and process_album immediately uses os.path.splitext(rar_name)[0] at L286, which requires a string archive name. This is an active contradiction between the documented intent and actual behavior.
When --lyrics is used, the script sends track title and artist metadata to external lyric providers, which can disclose a user's media library contents to third parties without an in-context privacy notice or confirmation. In a local media-processing skill this is more sensitive than usual because users may expect offline conversion only, making the external transmission easy to miss.
The docstring for inject_to_flac says DSF handling uses an ID3 USLT frame, implying lyrics are embedded into the DSF file itself. However, the DSF branch explicitly avoids modifying the file and instead creates a separate .lrc file, which is a direct contradiction between documentation and implementation.
This code emits multiple user-facing messages exclusively in Chinese, such as status, success, and error output, even though the script interface and top-level docstring are otherwise in English. That creates a language/locale policy issue because the skill imposes a specific language on users without opt-in or justification.
The skill fetches lyrics from third-party services but does not clearly warn that enabling this feature sends album/track metadata over the network. This can expose listening-library information or filenames to external services and may violate user privacy expectations in restricted environments.
The script emits Chinese-only messages such as '未找到歌词' and uses a Chinese line-count suffix '行' in normal runtime output. This enforces a specific language for part of the user experience without offering a language choice or documenting a locale-specific constraint.
The process_directory docstring says 'Process all FLAC files in a directory', but the implementation includes both .flac and .dsf files. This is an intent/documentation mismatch that could mislead users about what file types will be touched.
No suspicious patterns detected.