Back to skill

Security audit

Audio Creator · Foleyix

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Foleyix audio-generation integration that stores account tokens locally and can consume account quota only for requested generation workflows.

Install only if you want an agent to use your Foleyix account for audio work. Expect a browser-based device login, local token storage in a private Foleyix config directory, quota-consuming generation when you ask for audio, and private WAV downloads to paths you specify. For prompt drafting only, no login or generation should be needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (9)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/foleyix.mjs (reported line 193)May include surrounding context.

js
await privateDirectory(root);
  const directory = path.join(root, hash(origin));
  await privateDirectory(directory);
  config = { root, directory, credentials: path.join(directory, 'credentials.json'), journal: path.join(directory, 'requests.json'), lock: path.join(directory, '.lock') };
}
async function readPrivate(file, optional = true) {
  let handle;

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs the agent to use shell, network, and environment-backed capabilities to log in, check quota, generate audio, and download private WAV results, but it does not declare an explicit tool scope such as permissions or allowed-tools. That mismatch can let a host grant broader capabilities than reviewers or users expect, increasing the risk of unintended command execution, network access, or handling of private account data during operation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The short description is broad enough to match many generic audio-related requests, which can cause the skill to be invoked in situations the user did not clearly intend. Because the skill can prepare prompts and potentially generate/download private audio results, overbroad routing increases the chance of unintended access to external services or execution of higher-impact actions under ambiguous user requests.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/capabilities.md (reported line 40)May include surrounding context.

md
选公开样例时区分原始提示词和声音结果,取组织方式,不搬入无关台词、品牌或场景。已有脚本优化器的原则是保留全部说出的文字、原语言、参考标记和完整约束,不填补未给出的创意;显式创作请求则可以按授权范围写新内容。

本地依据(有仓库时再查看):`app/lib/audio-input.ts`、`app/lib/contracts.ts`、`app/server/generations.ts`、`workers/generation-workflow.ts`、`app/server/prompt-optimization.ts`、`app/lib/professional-split.ts`、`skills/audiocreator-foleyix/SKILL.md`、`docs/voice-library.md`、`docs/bgm-generator.md`。

## 保持同步

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The example explicitly specifies '中文双主播旅行播客开场', which indicates a fixed language requirement in the skill content. Under the policy, forcing a specific language without user opt-in or a clear region-specific justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire skill specification is written as a prescriptive Chinese-language instruction set, including explicit guidance like preserving lyric language and writing prompts in Chinese-oriented terminology, but it does not indicate that use of Chinese is optional or limited to a China-specific deployment. This can amount to a language/locale policy violation because it appears to force a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE (reported line 7)May include surrounding context.

text
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

Line L10 states that the model officially lists only Chinese and English, while other languages merely require trial verification. This is a natural-language locale policy constraint presented as a default limitation, and the file does not frame it as a user choice or a clearly justified region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file contains natural-language guidance exclusively in Chinese, with no indication that users may choose another language or that the skill is region- or locale-specific. Under the policy rule for language or locale constraints, forcing a specific language without user opt-in can be a policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.