Back to skill

Security audit

Iflytek Speed Transcription

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent iFLYTEK transcription skill, but users should know it uploads selected audio to a third-party API and currently works as MP3-only despite broader claims.

Install only if you are comfortable sending the selected MP3 audio and related metadata to iFLYTEK/XFYun using your XFEI credentials. Avoid confidential, regulated, or non-consented recordings unless your policy allows that provider, and use a virtual environment with pinned dependencies where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:8
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code generally matches the stated primary purpose of transcribing audio with the iFLYTEK/XFYun speed transcription service, including upload, task creation, polling, and result parsing. However, there are material description-behavior mismatches. Most importantly, the transcribe() method explicitly rejects any file whose extension is not .mp3, contradicting the declared support for WAV/PCM/MP3. The create_task() method also hardcodes format='audio/mp3' and encoding='lame', reinforcing that only MP3 is actually handled by this implementation. Additionally, the description claims automatic language detection, but the code exposes --language with a default of zh_cn and never performs any detection logic. These are not minor implementation details; they change what users can actually do with the skill. There is no evidence of unrelated malicious or undeclared exfiltration behavior beyond the expected API calls for transcription.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly states that audio is sent to third-party iFLYTEK endpoints, but it does not provide a clear user-facing privacy or data-transmission warning before use. Because audio may contain sensitive personal, medical, legal, or business information, users could unknowingly transmit regulated or confidential data to an external service.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents use of environment variables, network access, and output file writing, but it does not declare explicit tool permissions or allowed-tools scope. This weakens least-privilege controls and makes it harder for a host system or reviewer to understand and constrain what the skill can do, increasing the risk of unintended file writes or outbound data transfer.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill handles potentially sensitive audio such as meetings, interviews, medical consultations, and legal proceedings, yet it does not clearly warn users that recordings are uploaded to a third-party service. This creates a significant privacy and compliance risk because users may disclose confidential or regulated data without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill uploads user-provided audio to an external third-party transcription service, but the code provides no explicit notice at the point of use that local audio will leave the system. In an agent-skill context, this matters because audio may contain sensitive conversations, personal data, or regulated content, and users may reasonably assume local-only processing unless clearly told otherwise.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code sets default transcription parameters to zh_cn and mandarin, and the CLI repeats zh_cn as the default. This enforces a specific language/locale behavior by default rather than asking the user to choose or clearly opt in, which matches the language/locale policy violation rule.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a transcription skill for WAV, PCM, and MP3 inputs, but the transcribe workflow explicitly rejects any file whose extension is not .mp3. This is a direct behavior mismatch at the skill level because users invoking the skill for WAV or PCM transcription would be told the format is unsupported.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The command-line description says 'Transcribe audio files' and the positional argument is documented generically as a 'Path to audio file', which implies normal support for common audio formats. However, the core transcribe method rejects every non-MP3 file, so the inline documentation overstates what the program actually accepts.

Content

No source excerpt is available for this finding.

Tainted flow: 'result' from requests.post (line 366, network input) → pathlib.Path.write_text (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/transcribe.py (reported line 588)May include surrounding context.

python
if args.output:
                output_path = Path(args.output)
                if args.output_format == "json":
                    output_path.write_text(
                        json.dumps(result, ensure_ascii=False, indent=2),
                        encoding='utf-8'
                    )

Tainted flow: 'text' from requests.post (line 577, network input) → pathlib.Path.write_text (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/transcribe.py (reported line 593)May include surrounding context.

python
encoding='utf-8'
                    )
                else:
                    output_path.write_text(text, encoding='utf-8')
                print(f"\nSaved to: {args.output}")

    except Exception as e:

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file includes substantial Chinese-only user-facing guidance such as the error table's friendly prompts and the FAQ section, while the rest of the skill is primarily in English. This creates a language-policy concern because the skill imposes a specific language for part of the experience without explicitly asking for user preference or stating that the skill is intended for Chinese-speaking users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The script writes transcription text or JSON results to a user-specified path, which is a file write operation covered by the warning rule. Although the save action is user-requested via --output, there is no prior comment, help text, or disclosure that the tool will create or overwrite a file at the provided path.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.