Back to skill

Security audit

Speak

Security checks for vulnerabilities and agentic risk

Overview

This is a speech-formatting skill with scoped preference memory and no executable payload; its flagged behaviors are mostly disclosed and aligned with making text sound better aloud.

Before installing, be aware that the skill can create persistent speech preferences such as voice, locale, pronunciation fixes, quiet hours, and engine notes. Review any cloud TTS engine choice separately because spoken text sent to a cloud provider may leave your machine, and avoid caching or speaking sensitive content unless your context is private.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Line L24 instructs the skill to 'prefer lower-pitched voices' for a class of users, which is a natural-language locale/style policy decision applied categorically rather than offered as a user choice. Under the policy, forcing a language or presentation variant without opt-in can be a violation when the user is not given control.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

Line L07 states that locale in config sets the default, which establishes a language/locale behavior absent any explicit user choice in this file. Under the policy criteria, locale constraints should offer user choice or clearly document justified opt-in behavior; this instruction instead defaults the behavior unilaterally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The guidance says to convert times to the user's local time and to avoid forcing am/pm onto a 24-hour user, which imposes locale-specific behavior as a default. This is a natural-language locale policy concern because the file does not indicate user opt-in or an explicit language/locale choice in this document.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 145)May include surrounding context.

md
- Language switch request → one signal = locale/language update (`multilingual.md`).
- Everything else (rate, style, check-ins, verbosity, notification muting) → two-signal rule (SKILL.md rule 7): comply the first time, confirm and store on the second.
- Situational requests ("just this once, faster", "serious tone for this document") → comply, store nothing.
- Declared settings (voice, rate baseline, time format, locale) → `config.yaml`; observed patterns, lexicon, and engine test results → `preferences.md`. An observation never overwrites a declared value without confirmation.

If the user has said nothing, store nothing.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · setup.md (reported line 24)May include surrounding context.

md
- Language switch request → one signal = locale/language update (`multilingual.md`).
- Everything else (rate, style, check-ins, verbosity, notification muting) → two-signal rule (SKILL.md rule 7): comply the first time, confirm and store on the second.
- Situational requests ("just this once, faster", "serious tone for this document") → comply, store nothing.
- Declared settings (voice, rate baseline, time format, locale) → `config.yaml`; observed patterns, lexicon, and engine test results → `preferences.md`. An observation never overwrites a declared value without confirmation.

If the user has said nothing, store nothing.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This markdown file discusses cloning a real person's voice and requires documented consent, but it does not explicitly warn that voice cloning involves handling highly sensitive biometric-like personal data and may create privacy or misuse risks. Under the markdown-specific warning criterion, skills describing behavior that could affect privacy should disclose those risks to users more directly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The default configuration hard-codes locale: en-US, which imposes a specific language/locale choice if no user preference is present. The file does not offer an explicit user opt-in or alternative locale selection at this point, so it can conflict with language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.