Back to skill

Security audit

moss-transcribe-diarize

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward audio transcription helper that sends user-selected audio to a disclosed MOSS/MOSI transcription API and saves the returned transcript locally.

Install only if you intend to use the MOSS/MOSI remote transcription service and are comfortable sending the selected audio, URLs, or base64 audio data to that provider. Avoid submitting confidential, regulated, or third-party recordings unless you have authorization and understand the provider's retention and privacy terms.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tainted flow: 'headers' from os.getenv (line 82, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/transcribe.py (reported line 88)May include surrounding context.

python
}

    try:
        r = requests.post(TRANSCRIBE_URL, headers=headers, json=payload, timeout=args.timeout)
    except requests.RequestException as e:
        fail(f"request failed: {e}")

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill invokes a Python script that can read local files, write output files, access environment variables for API keys, and make outbound network requests, but it does not declare any explicit tool scope or permissions. This weakens enforcement and transparency, increasing the chance that an agent platform grants broader access than users expect or that risky operations occur without clear consent boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill processes potentially sensitive audio and sends it to an external API endpoint, but the description does not clearly warn users that their audio content and derived transcription data will leave the local environment. In the context of meetings, interviews, and multi-speaker conversations, this can expose confidential, personal, or regulated information without sufficiently informed user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill transmits raw audio or local file contents to an external third-party transcription endpoint, and this may include sensitive conversations, personal data, or regulated content. In a skill context, users may invoke local-file transcription without fully appreciating that the content leaves the local environment, so the absence of an explicit warning/consent step increases privacy and compliance risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/transcribe.py (reported line 88)May include surrounding context.

python
}

    try:
        r = requests.post(TRANSCRIBE_URL, headers=headers, json=payload, timeout=args.timeout)
    except requests.RequestException as e:
        fail(f"request failed: {e}")

Tainted flow: 'data' from requests.post (line 93, network input) → pathlib.Path.write_text (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/transcribe.py (reported line 102)May include surrounding context.

python
out_path = Path(args.out)
    out_path.parent.mkdir(parents=True, exist_ok=True)
    out_path.write_text(json.dumps(data, ensure_ascii=False, indent=2), encoding="utf-8")

    segs = normalize_segments(data)

Static analysis

No suspicious patterns detected.