Back to skill

Security audit

Podcast Summarize

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward podcast-summary helper, but users should be careful with third-party transcription tools and package installs.

Before installing, understand that full functionality depends on external tools. Use a virtual environment, install reviewed and pinned transcription/download packages, and avoid sending private or sensitive recordings to an external API unless you explicitly intend to do so.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/technical.md:12
Finding

Unpinned and Ambiguous Third-Party Dependencies

Content
View full analysis

Vulnerability Details

File Location: references/technical.md, lines 12–20
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code:

bash
# Install yt-dlp
pip install yt-dlp

# Install Whisper
pip install openai-whisper

# Or use the CLI version
pip install whisper

Technical Analysis

The documented installation commands retrieve mutable latest versions of third-party packages without version constraints or integrity hashes. This makes installations non-reproducible and causes their security to depend on package-registry state at installation time.

The whisper package name is also ambiguous: the project does not establish that it is the canonical or reviewed implementation intended for this skill. Users could therefore install an unintended package. Python package installation may execute package-controlled build or installation logic, so a compromised release, dependency-confusion event, or mistaken package selection can become local code execution.

The repository does not itself contain malicious dependency code, and the finding does not establish that any listed package is currently compromised. The risk arises from the unsafe dependency acquisition instructions.

Attack Path

  1. An attacker compromises a referenced package, one of its transitive dependencies, or publishes an unintended package under an ambiguous name.
  2. A user follows the documented command, such as pip install whisper.
  3. pip resolves the current package version from the configured package index without checking a project-provided version pin or hash.
  4. Package-controlled build or installation logic executes in the user's environment.
  5. Malicious code runs with the privileges of the account performing the installation.

Impact Assessment

Successful exploitation could execute arbitrary code with the installing user's privileges. Depending on those privileges and t ...[truncated 369 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the ambiguous pip install whisper instruction and identify the exact canonical implementation and publisher.
  2. Pin every direct dependency to a reviewed version rather than installing an unconstrained latest release.
  3. Maintain an audited lock file that records transitive dependencies.
  4. Require package hashes, for example through a hash-locked requirements file and pip install --require-hashes.
  5. Document the trusted package index or canonical source repository and avoid unreviewed alternate indexes.
  6. Install dependencies in a dedicated, least-privileged virtual environment rather than as root or into the system Python environment.
  7. Add an update process that reviews release notes, provenance, and vulnerability advisories before changing pinned versions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared purpose is a podcast summarization skill that supports multiple input sources and produces concise insights. The supplied shell script only accepts a local file path, checks that the file exists, uses ffprobe to read duration, and prints example commands for external transcription tools. It has no summarization logic, no transcription implementation, and no handling for URLs, RSS feeds, or podcast links. This is a material description-behavior mismatch in primary purpose and supported capabilities.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/transcribe.sh (reported line 22)May include surrounding context.

sh
DURATION=$(ffprobe -v error -show_entries format=duration -of default=noprint_wrappers=1:nokey=1 "$AUDIO_FILE" 2>/dev/null)
echo "Audio duration: $DURATION seconds"

# For now, output instructions for using Whisper
# TODO: Integrate actual Whisper transcription
echo ""
echo "To transcribe this file, run:"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises handling local audio files and external URLs but does not warn users that content may be downloaded, processed locally, or transmitted to third-party transcription services such as Whisper APIs. This creates a meaningful privacy and data-governance risk, especially if users provide sensitive recordings or internal file paths without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prescribed summary template is entirely in Chinese, which implicitly forces a specific language for responses. Although the process notes support multiple languages for transcription, the skill does not offer a language choice or state that Chinese output is optional.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

Broad trigger phrases like 'summarize this podcast' can cause the skill to activate for ordinary requests without clear scope checks, increasing the chance it processes unintended local files or external links. In a skill that may download media or send content to transcription tools, ambiguous invocation raises the risk of over-collection and accidental data handling.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.