Back to skill

Security audit

Cd2flac

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly does what it says, but it can delete source audio files unsafely and sends music metadata to external lyric services with weak disclosure and an insecure HTTP fallback.

Install only if you are comfortable with it modifying your music files. Run on backed-up copies first, prefer --dry-run and --keep-wav --keep-cue, avoid --delete-rar unless you have verified outputs, and use --lyrics or lyric.py only if you accept sending track metadata to Netease/Kugou, including an insecure HTTP Kugou fallback.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/cd2flac.py:450
Finding

Source files are deleted even when audio conversion fails

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/lyric.py:83
Finding

Kugou lyric queries and responses use unencrypted HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/lyric.py:20
Finding

Reusable Netease service token is embedded in source code

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented purpose centers on archive extraction and audio conversion, but the analyzed behavior reportedly focuses on network lyric lookup and metadata injection while omitting the core advertised conversion workflow. This mismatch is dangerous because reviewers or users may grant trust and permissions based on the stated purpose while the actual behavior performs different operations, including outbound network activity and media metadata modification.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill documentation declares no explicit tool scope despite requiring shell execution, file reads/writes, and network access. In an agent environment, missing permissions metadata can cause the skill to run with broader-than-expected capabilities, reducing reviewability and increasing the chance of unsafe execution or abuse.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

md
## Requirements

- **System packages**: `unrar`, `cuetools`, `shntool`, `flac`
- Install: `sudo apt-get install -y unrar cuetools shntool flac`

## Python dependencies

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/cd2flac.py (reported line 79)May include surrounding context.

python
## Requirements

- **System packages**: `unrar`, `cuetools`, `shntool`, `flac`
- Install: `sudo apt-get install -y unrar cuetools shntool flac`

## Python dependencies

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/cd2flac.py (reported line 85)May include surrounding context.

python
## Requirements

- **System packages**: `unrar`, `cuetools`, `shntool`, `flac`
- Install: `sudo apt-get install -y unrar cuetools shntool flac`

## Python dependencies

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README advertises deletion of source archives and cleanup of original WAV/CUE files without a prominent warning about irreversible data loss. This creates a safety risk because users may invoke destructive options without understanding that original media or archives could be permanently removed.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/cd2flac.py (reported line 56)May include surrounding context.

python
else:
        kwargs.update(stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL)
    try:
        result = subprocess.run(cmd, **kwargs)
    except subprocess.TimeoutExpired:
        return -1, "", "TIMEOUT"
    if capture:

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The --recursive help text at L395-L396 states the skill will process subdirectories as separate albums. But in recursive mode, main calls process_album(album_path, None, args) at L432, and process_album immediately uses os.path.splitext(rar_name)[0] at L286, which requires a string archive name. This is an active contradiction between the documented intent and actual behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

When --lyrics is used, the script sends track title and artist metadata to external lyric providers, which can disclose a user's media library contents to third parties without an in-context privacy notice or confirmation. In a local media-processing skill this is more sensitive than usual because users may expect offline conversion only, making the external transmission easy to miss.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The docstring for inject_to_flac says DSF handling uses an ID3 USLT frame, implying lyrics are embedded into the DSF file itself. However, the DSF branch explicitly avoids modifying the file and instead creates a separate .lrc file, which is a direct contradiction between documentation and implementation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code emits multiple user-facing messages exclusively in Chinese, such as status, success, and error output, even though the script interface and top-level docstring are otherwise in English. That creates a language/locale policy issue because the skill imposes a specific language on users without opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill fetches lyrics from third-party services but does not clearly warn that enabling this feature sends album/track metadata over the network. This can expose listening-library information or filenames to external services and may violate user privacy expectations in restricted environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script emits Chinese-only messages such as '未找到歌词' and uses a Chinese line-count suffix '行' in normal runtime output. This enforces a specific language for part of the user experience without offering a language choice or documenting a locale-specific constraint.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The process_directory docstring says 'Process all FLAC files in a directory', but the implementation includes both .flac and .dsf files. This is an intent/documentation mismatch that could mislead users about what file types will be touched.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.