Back to skill

Security audit

Bot Voice Config Clean

Security checks for vulnerabilities and agentic risk

Overview

This skill appears purpose-aligned, but it handles third-party credentials, sends audio through external services, persists configuration, and has avoidable security weaknesses that users should review before installing.

Review this before installing. Use least-privilege Feishu and Volcengine credentials, avoid putting real secrets in the JSON config, restrict any local secret file permissions, and assume test operations contact Volcengine and Feishu. Avoid running the script as root or on shared machines until the temporary-file handling is fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:56
Finding

Documentation Encourages Plaintext Storage of Reusable Service Credentials

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/voice-config.sh:299
Finding

Predictable Shared Temporary Files Permit Symlink-Based File Overwrite

Content
View full analysis
"$output_file" ``` The Opus path is overwritten by `ffmpeg` without exclusive creation: ```bash ffmpeg -i "$input_file" -c:a libopus -b:a 32k "$output_file" -y 2>/dev/null ``` ### Technical Analysis Process IDs are not random secrets and can be observed or predicted by other local users. The script does not use `mktemp`, exclusive file creation, a private temporary directory, or symbolic-link checks. On systems where `/tmp` is shared, an attacker may create one of the anticipated paths as a symbolic link before the script writes to it. Shell output redirection normally follows symbolic links, and `ffmpeg -y` explicitly permits replacement of an existing output path. Consequently, the test operation may write attacker-influenced audio data to another file accessible to the account running the Skill. The final `rm -f` removes the temporary pathname itself. The primary security issue is the earlier write through the attacker-controlled symbolic lin ...[truncated 1603 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly promotes generating test audio and sending it to Feishu, but it does not clearly warn users that synthesized voice content will be transmitted to a third-party messaging platform. This can lead to unintentional disclosure of sensitive prompts, personal data, or internal content during testing, especially in an agent-skill context where users may assume local-only processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README shows API keys, app secrets, and user IDs stored in a local JSON config file without an explicit warning that these are sensitive credentials. Users may copy this pattern directly, increasing the chance of secrets being left in plaintext on disk, accidentally committed to repositories, or exposed through backups and logs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly instructs users to export sensitive credentials such as API keys and app secrets into shell startup files and to place secrets into a config file, but provides no warning about secure storage, file permissions, secret rotation, or avoiding accidental commits/logging. This can lead to credential exposure through shell history, inherited environment variables, readable dotfiles, process inspection, backups, or checked-in config files, especially in shared or developer workstation environments.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases are broad natural-language terms like '设置音色' and '默认音色' that can plausibly appear in ordinary conversation, increasing the chance the skill activates without clear user intent. In a skill that can write configuration and send external test audio, accidental invocation can lead to unintended state changes or outbound actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill clearly describes saving configuration, using API credentials, and sending generated audio to Feishu, but it does not present a centralized, explicit risk notice about secret handling, local file modification, and data egress. This makes users less likely to understand that invoking the skill may persist changes and transmit content to third-party services.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 262)May include surrounding context.

md
## 配置文件位置

- **主配置**: `~/.openclaw/workspace/config/bot-voice-config.json`
- **技能文档**: `~/.openclaw/workspace/skills/bot-voice-config/SKILL.md`

## 自动化脚本

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

Entries such as '性感魅惑', '娇喘女声', and similar intimate-roleplay labels present potentially sensitive output modes, but the document provides no warning or usage guidance. For markdown skill documentation, omission of user-facing warnings about behavior that may affect safety expectations or appropriateness can be a quality and safety issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script's user-facing comments and command aliases are entirely in Chinese, and later output/help text also assumes Chinese-only interaction. This can violate language/locale policy when a skill forces a specific language without opt-in or justification that it is intended only for a Chinese-language environment.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/voice-config.sh (reported line 69)May include surrounding context.

sh
return 1
    fi
    
    TOKEN=$(curl -sL -X POST 'https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal' \
      -H 'Content-Type: application/json' \
      -d "{
        \"app_id\": \"$FEISHU_APP_ID\",

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The script sends user-provided text and selected speaker metadata to an external TTS provider, and explicitly disables the markdown filter in the request additions. In this skill context, external transmission is expected, but the lack of consent/validation and deliberate reduction of content filtering increases the risk of sending sensitive or unsafe content to a third party.

Content

Scanner excerpt · scripts/voice-config.sh (reported line 91)May include surrounding context.

sh
print_info "正在生成 TTS 音频..."
    
    RESPONSE=$(curl -sL -X POST 'https://openspeech.bytedance.com/api/v3/tts/unidirectional' \
      -H "x-api-key: $VOLC_API_KEY" \
      -H "X-Api-Resource-Id: $VOLC_RESOURCE_ID" \
      -H 'Content-Type: application/json' \

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/voice-config.sh (reported line 178)May include surrounding context.

sh
print_info "正在发送语音消息..."
    
    SEND_RESPONSE=$(curl -sL -X POST 'https://open.feishu.cn/open-apis/im/v1/messages?receive_id_type=open_id' \
      -H "Authorization: Bearer $TOKEN" \
      -H 'Content-Type: application/json' \
      -d "{

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The README presents the skill name, instructions, and in-product usage phrases entirely in Chinese, including example invocations, but does not state that the skill is intentionally limited to Chinese-speaking users or offer an opt-in language choice. This can constitute a language/locale policy issue when a skill appears to enforce a single language by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

整份技能说明、触发词、示例回复和命令语法均以中文固定呈现,没有说明是否支持其他语言或允许用户按偏好切换语言。按照语言/区域策略,这种默认强制单一语言且未提供用户选择的做法可能构成自然语言政策问题。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This markdown file documents voice options and repeatedly includes ASMR-oriented voices and emotional styles such as '低语 (ASMR)' without any warning about how these styles may produce intimate, suggestive, or privacy-sensitive audio output. Under the markdown-specific warning rule, descriptions that can affect user expectations or content sensitivity should disclose such behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The display name, description, and several keywords are presented only in Chinese, which can amount to forcing a specific language for users who may not have opted into that locale. The file does not indicate that the skill is region-specific or that users can choose another language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The script updates and overwrites the persistent config file and creates backups via cp/mv/jq, but there is no prior warning in the file header or usage comments that running set will modify files under the user's home directory. Although a success message is printed afterward, the skill lacks advance disclosure in its description/comments about this file-modifying behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The bind command writes to the user's config file and backup file, changing default and bot-specific speaker mappings. The file includes runtime status output, but its top-level description and usage comments do not warn users that invoking bind will persistently alter configuration on disk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.