Back to skill

Security audit

News Summary

Security checks for vulnerabilities and agentic risk

Overview

This news-summary skill is coherent and purpose-aligned, with minor privacy and temporary-file cautions for optional voice summaries.

Installers should treat this as a public-news helper. Use the voice-summary option only when sending the summary text to OpenAI TTS is acceptable, and consider changing the fixed /tmp/news.mp3 example to a unique private temporary file before operational use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:70
Finding

Predictable Shared Temporary File for Generated Audio

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 70-81
Vulnerability Type: Unsafe temporary-file handling
Risk Level: Low

Complete Code Snippet:

bash
curl -s https://api.openai.com/v1/audio/speech \
  -H "Authorization: Bearer $OPENAI_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "model": "tts-1-hd",
    "input": "<news summary text>",
    "voice": "onyx",
    "speed": 0.95
  }' \
  --output /tmp/news.mp3

Technical Analysis

The voice-generation workflow writes its result to the fixed, predictable path /tmp/news.mp3. Temporary directories are commonly shared by multiple users and processes. Reusing a known filename creates opportunities for file collisions, cross-run interference, and symbolic-link attacks.

If the execution environment permits following attacker-created symbolic links in /tmp, another local process could create /tmp/news.mp3 as a link to a different file before the command runs. The curl --output operation could then truncate or overwrite that target under the privileges of the account executing the Skill. Some operating systems mitigate this scenario through protected-symlink settings, but the Skill should not rely exclusively on platform-specific protections.

Independently of symbolic-link protections, concurrent Skill executions can overwrite the same output, expose one invocation's generated audio to another invocation, or cause the wrong audio file to be sent to a user.

Attack Path

  1. A local attacker or competing process predicts that the Skill will write to /tmp/news.mp3.
  2. Before voice generation begins, it creates a conflicting file or, where platform protections allow, a symbolic link at that path.
  3. The Skill invokes curl and writes the generated audio to the attacker-controlled filesystem entry.
  4. The operation overwrites the conflicting file or follows the symbolic link to another file writable by th ...[truncated 723 chars]
Remediation
View remediation

Remediation Suggestions

  • Create a unique temporary file or private temporary directory for each invocation using mktemp.
  • Apply restrictive permissions with umask 077 so only the executing account can access generated audio.
  • Validate that temporary-file creation succeeds before passing the path to curl.
  • Remove the generated file through a cleanup trap when processing completes.
  • Avoid reusing temporary paths across users, sessions, or concurrent executions.
  • Where supported, use exclusive file creation and reject symbolic links.

Example hardened workflow:

bash
umask 077
tmp_dir="$(mktemp -d)" || exit 1
trap 'rm -rf -- "$tmp_dir"' EXIT
output_file="$tmp_dir/news.mp3"

curl --fail --silent --show-error \
  https://api.openai.com/v1/audio/speech \
  -H "Authorization: Bearer $OPENAI_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "model": "tts-1-hd",
    "input": "<news summary text>",
    "voice": "onyx",
    "speed": 0.95
  }' \
  --output "$output_file"
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description contains broad trigger phrases like 'news updates,' 'daily briefings,' and 'what's happening in the world,' which can match many ordinary user requests. Overly broad activation increases the chance the skill is invoked when the user did not intend it, causing unintended network access to third-party news feeds and unexpected tool behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The voice-summary workflow sends generated summary text to an external OpenAI TTS API without an explicit notice or consent step. If the summary includes sensitive, user-specific, or confidential content, this creates an unannounced third-party data transfer and privacy risk, especially because the skill also writes the output to a temporary local file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.