Back to skill

Security audit

SpeakNotes: YouTube, Audio & Document Summaries

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed SpeakNotes API integration that uses a user-provided API key to create, upload, poll, and retrieve notes and folders.

Install this only if you are comfortable giving OpenClaw a SpeakNotes API key that can create uploads and read notes and folders available to that key. Use a scoped or revocable API key if SpeakNotes supports it, and ask the agent to access existing notes or folders only when needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest/openAPI context describes broad direct API use without clear trigger constraints, approved use cases, or boundaries on when the agent may call these endpoints. In combination with bearer-authenticated access and overbroad endpoints, the lack of invocation guardrails makes unintended or excessive data access more likely.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description says it is for direct SpeakNotes transcript/summary generation, but the OpenAPI spec also grants broad read access to existing notes and folders. This creates an over-scoped integration that can be used for unrelated account content discovery, increasing the chance of unauthorized data exposure if the agent is invoked in contexts beyond the user's intent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Exposing list/get operations for notes and folders is not necessary for a skill whose stated purpose is generating transcripts and summaries from supplied inputs. Those endpoints enable inventorying and retrieving potentially sensitive user content, so a compromised or overly-permissive agent could access unrelated account data under the same bearer credential.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.