Back to skill

Security audit

Assemblyai Transcriber

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a normal cloud transcription integration, but users should understand that audio may be sent to AssemblyAI.

Install only if you are comfortable sending selected audio or voice messages to AssemblyAI for transcription. Avoid using it on confidential, regulated, or non-consenting speakers' recordings unless you have permission and have reviewed AssemblyAI's data-handling terms.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The README instructs users to configure an AssemblyAI API key and use the skill for transcription, but it does not clearly warn that submitted audio is sent to a third-party service for processing. This can cause users to upload sensitive meetings, interviews, or voice messages without informed consent or awareness of external data handling, creating privacy and compliance risk.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
Advertising Telegram voice message support without a privacy warning increases the risk that users will casually forward personal or sensitive voice messages for third-party processing. Because voice messages often contain private content and may involve non-consenting speakers, the missing disclosure is especially risky in this context.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill sends user-provided audio to AssemblyAI, a third-party service, but the description does not clearly warn users that potentially sensitive voice content leaves the local environment. This creates a privacy and compliance risk because users may unknowingly transmit confidential meetings, interviews, or personal voice messages to an external processor.

Static analysis

No suspicious patterns detected.