Back to skill

Security audit

Percept Listen

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent wearable-transcription purpose, but it asks users to capture and expose sensitive ambient conversation data without enough consent, authentication, or retention safeguards.

Review carefully before installing. Only use this where all recorded participants have been informed as required by law, install Percept in an isolated environment with a pinned trusted version, protect the webhook with authentication or tunnel access controls, and define how transcripts will be deleted or retained.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Unpinned Third-Party Package Installation

Content
View full analysis
/webhook/transcript` ## Setup ```bash # Install Percept pip install getpercept ``` ``` ### Technical Analysis The Skill directs users to install `getpercept` from pip's default configured package index without specifying a reviewed version or an integrity hash. Consequently, the dependency resolved during installation may differ from the version that was reviewed when the Skill was published. Python packages can execute package-controlled code during build or installation. They also deliver executable modules and command-line entry points that users subsequently run. A compromised maintainer account, malicious package release, package-index compromise, or unexpected upstream update could therefore introduce arbitrary executable code. The Skill does link to an expected GitHub project, but it does not verify that the package downloaded by pip corresponds to a particular reviewed commit or release. ### Attack Path 1. An attacker compromises the package publisher, distribution channel, or a future upstream release. 2. The attacker publishes a modified `getpercept` package containing malicious installation or runtime code. 3. A user follows the Skill and runs `pip install getpercept`. 4. Pip resolves and installs the attacker-controlled release because no version or hash is specified. 5. Malicious code executes during installation or when the user invokes `percept start`. ### Impact Assessment Successful exploitation could execute arbitrary code with the privileges of the account performing the inst ...[truncated 315 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:14
Finding

Sensitive Transcript Receiver Exposed Without Documented Authentication Controls

Content
View full analysis
/webhook/transcript` ## Setup ```bash # Install Percept pip install getpercept # Start the receiver (default port 8900) percept start # Or run directly PYTHONPATH=. python -m uvicorn src.receiver:app --host 0.0.0.0 --port 8900 ``` Configure a tunnel (Cloudflare, ngrok, Tailscale) so Omi can reach your local server. ``` ### Technical Analysis The documented command binds the receiver to `0.0.0.0`, making it reachable through every available network interface. The instructions then direct users to expose the transcript webhook through a tunnel. No requirement is given for webhook signatures, authentication tokens, source restrictions, replay prevention, request-size limits, or strict request validation. This creates an externally reachable ingestion path for sensitive ambient-conversation data. If the underlying receiver does not independently implement protections that are not documented here, an unauthenticated remote party could submit forged transcript events. Such events could be persisted in SQLite, indexed for search, and treated as genuine conversation records by downstream agents. The statement that “all processing stays local” is also incomplete in the documented deployment model: transcripts are sent from the phone to an endpoint through a tunnel and therefore traverse network and tunnel infrastructure, even if storage and subsequent processing occur locally. ### Attack Path 1. A user starts Uvicorn with `--host 0.0.0.0 --port 8900`. 2. The user exposes the receiver using a Cloudflare, ngrok, Tailscale, or similar tunnel. 3. An attacker obtains or discovers the public webhook URL through logs, URL leakage, endpoint enumeration, or accident ...[truncated 1222 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill describes ambient conversation capture and searchable transcript storage but does not clearly warn users about privacy, consent, bystander recording, retention, or legal implications. Because the skill is specifically designed to capture nearby speech, the lack of prominent warning increases the risk of covert or uninformed surveillance and unauthorized collection of sensitive conversations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation guidance uses broad natural-language triggers like 'start listening' and 'turn on the mic' for a skill that enables ambient audio capture. In an agent ecosystem, such phrases can be invoked accidentally, socially engineered, or triggered without sufficiently explicit consent, leading to unintended recording or transcription of nearby conversations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.