T09 · Insecure Skill Coding Practices
- Location
aliyun_pure_asr.py:89- Finding
Converted Voice Recordings Persist in Predictable Local Files
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This voice transcription skill is purpose-aligned, but it needs Review because it uploads voice audio to Aliyun, recommends broad cloud permissions, and can leave converted audio files on disk despite claiming no local storage.
Review before installing. Use a dedicated low-privilege Aliyun RAM user, rotate and protect the AccessKey, enable the skill only in channels where users understand voice messages will be sent to Aliyun, and treat converted audio files as sensitive until cleanup behavior is fixed.
aliyun_pure_asr.py:89Converted Voice Recordings Persist in Predictable Local Files
SKILL.md:27Aliyun Setup Instructions Grant Excessive NLS Permissions
The supplied code chunk does not implement the declared ASR/transcription functionality at all. While it also does not show any undeclared or harmful capability, the actual behavior visible here is effectively a no-op placeholder, which is materially different from the declared primary purpose of voice message transcription. Because the assessment is limited to the provided chunk, this should be flagged as a mismatch between description and demonstrated behavior.
The setup and usage text does not clearly warn that user audio will be transmitted to Aliyun for third-party processing, which is a material privacy and compliance concern. In voice workflows, silent external transfer of user content can expose sensitive personal or business information and may violate consent, policy, or regulatory requirements.
The skill metadata declares no explicit tool scope or permissions, yet the documented behavior clearly implies reading a local config file, making outbound network requests to Aliyun, and potentially invoking shell-related setup steps. In an agent ecosystem, missing scope declarations weaken reviewability and sandbox enforcement, increasing the risk that the skill can access resources beyond what users or operators expect.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
chmod 600 /root/.openclaw/aliyun-asr-config.json
The skill is described as automatically activating for voice messages from any supported channel, without clear boundaries, consent gates, or per-channel constraints. Overly broad auto-triggering can cause unintended capture and transmission of user audio, increasing privacy and misuse risks, especially in multi-channel deployments where expectations differ.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
if audio_file.endswith('.ogg'):
wav_file = audio_file.replace('.ogg', '.wav')
# 转换为16kHz单声道WAV
subprocess.run([
'ffmpeg', '-i', audio_file, '-ar', '16000', '-ac', '1',
'-f', 'wav', wav_file
], check=True, capture_output=True)
The skill sends raw audio content to a remote Aliyun ASR endpoint, but the CLI usage and code provide no explicit notice that potentially sensitive voice data leaves the local environment. In a transcription skill this behavior is expected functionally, but the absence of disclosure creates a privacy and data-handling risk, especially for confidential or regulated audio.
The module docstring states in Chinese that this is an 'Alibaba Cloud pure ASR skill' and that it only provides speech recognition. The file provides no indication that users can choose another language or locale, which can be a natural-language policy issue when a skill appears to enforce a specific language context without opt-in.
The only natural-language documentation in this file is written in Chinese and does not indicate that language selection is optional or tied to a documented regional requirement. Under the language/locale policy rule, this can be considered a locale constraint presented without user opt-in or justification.
The script reads long-lived cloud credentials from /root/.openclaw/aliyun-asr-config.json, including access_key_secret. While the code prints the expected fields, it does not warn that the file contains sensitive credentials or advise secure storage and restricted permissions.
The manifest and module docstring describe a pure voice-to-text skill with no extra functionality, but the implementation invokes an external program via subprocess to perform media conversion. While related to transcription, process execution is a distinct capability that is not explicitly justified by the stated scope and expands operational risk beyond a straightforward API client.
The manifest-like JSON sets the region to "cn-shanghai", which is a locale-specific setting expressed in natural language/config text. Under the policy rule, forcing a specific locale or region without user choice or documented justification can be a natural-language policy violation.
The module docstring and function docstring describe the skill exclusively in Chinese, including the interface purpose and argument semantics. This creates a language-specific constraint in the natural-language surface of the skill without indicating that users can choose another language or that the limitation is intentional and justified.
No suspicious patterns detected.