Back to skill

Security audit

Novel To Audiobook Hznuyx17

Security checks for vulnerabilities and agentic risk

Overview

This audiobook skill does what it claims, but it sends manuscript text to external AI services and asks users to keep API keys in a local config file, so it needs review before use.

Install only if you are comfortable sending chapter text to DeepSeek and MiniMax and storing generated intermediates locally. Use throwaway or restricted API keys, avoid unpublished or confidential manuscripts unless the providers' terms are acceptable, keep config.json out of source control/backups, and manually clean temp_analysis.json, temp_audio, and temp_bgm after use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
config.json:4
Finding

API Credentials Stored in Plaintext Configuration

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/music_generator.py:132
Finding

Unvalidated Server-Provided URL Download Enables Client-Side SSRF

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/audio_assembler.py:17
Finding

Unpinned Runtime Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This mismatch becomes security-relevant because the skill presents itself as a normal audiobook generator while actually involving undeclared external network transmission of user-provided text to third-party TTS services. Users may consent to local media processing but not realize their manuscript or chapter content is being uploaded externally, creating a privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This mismatch becomes security-relevant because the skill presents itself as a normal audiobook generator while actually involving undeclared external network transmission of user-provided text to third-party TTS services. Users may consent to local media processing but not realize their manuscript or chapter content is being uploaded externally, creating a privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This mismatch becomes security-relevant because the skill presents itself as a normal audiobook generator while actually involving undeclared external network transmission of user-provided text to third-party TTS services. Users may consent to local media processing but not realize their manuscript or chapter content is being uploaded externally, creating a privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs sending full chapter text to DeepSeek for analysis, but the documentation does not clearly warn users that their manuscript content will be transmitted to an external API. For a novel-writing context, this is especially sensitive because unpublished creative work may contain private, proprietary, or monetizable content that users would not expect to leave their machine.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/music_generator.py (reported line 138)May include surrounding context.

python
# 尝试精确匹配和部分匹配
    for key, prompt in MOOD_PROMPT_MAP.items():
        if key in mood:
            return prompt
    return DEFAULT_PROMPT

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares capabilities to read user files, write output files, and send chapter content to external services, but it does not declare any tool scope or permission boundaries. This weakens user consent and platform control, making it easier for the skill to access files or exfiltrate chapter text without an explicit, reviewable capability declaration.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include broad everyday expressions such as '做成音频' or '语音版', which can cause accidental invocation in contexts where the user did not intend this skill. Because this skill reads files, writes outputs, and sends content to external APIs, accidental triggering can lead to unintended data disclosure or file operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill writes final outputs to the filesystem and retains intermediate JSON and audio artifacts, but this persistence is only mentioned later as a note and not surfaced as an operational warning. Temporary files can expose sensitive manuscript text, character metadata, or generated audio to other local users, backups, or unintended later reuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language documentation and CLI descriptions entirely in Chinese, including the module docstring and usage text. Under the policy, forcing a specific language without user choice is a locale/language policy concern, and there is no indication that the skill is region-specific or that users can select another language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sends full chapter text to DeepSeek's external API for processing, but there is no explicit user-facing notice or consent step before transmitting potentially sensitive or copyrighted content off-device. In a skill that processes user-supplied manuscripts or unpublished novels, this creates privacy, confidentiality, and data-governance risk even though the transmission is part of intended functionality.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This code performs external network transmission to api.deepseek.com, sending prompts that include the user's chapter text. External transmission is expected for an LLM-backed analyzer, but it is still security-relevant because it exposes user content to a third party and may violate privacy or confidentiality expectations if not tightly controlled.

Content

Scanner excerpt · scripts/chapter_analyzer.py (reported line 83)May include surrounding context.

python
def call_deepseek(system_prompt, user_prompt, api_key, model="deepseek-chat"):
    """调用 DeepSeek API 分析文本"""
    url = "https://api.deepseek.com/v1/chat/completions"
    headers = {
        "Authorization": f"Bearer {api_key}",
        "Content-Type": "application/json",

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file's natural-language interface is entirely in Chinese, including the top-level description, usage examples, and argument help context, with no indication that this skill is China-specific or that another language is available. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/music_generator.py (reported line 32)May include surrounding context.

python
SKILL_DIR = SCRIPT_DIR.parent
CONFIG_PATH = SKILL_DIR / "config.json"

MUSIC_URL = "https://api.minimaxi.com/v1/music_generation"

# 情绪 → 音乐 Prompt 映射
MOOD_PROMPT_MAP = {

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring, CLI descriptions, and embedded user-facing output are all written in Chinese, and the voice-selection logic is based on Chinese-character heuristics for role names. This enforces a specific language/locale experience without any opt-in or documented justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The script sends chapter text and an API key to a third-party TTS service, which is a genuine external data transmission. In the context of a novel-to-audiobook skill this is expected behavior, but it still creates privacy and data-handling risk because potentially sensitive or copyrighted chapter content is exported off-platform to an external provider.

Content

Scanner excerpt · scripts/tts_generator.py (reported line 33)May include surrounding context.

python
CONFIG_PATH = SKILL_DIR / "config.json"

# MiniMax TTS API
TTS_URL = "https://api.minimaxi.com/v1/t2a_v2"


def load_config():

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

All natural-language user-facing descriptions, prompts, and CLI help text in this file are fixed to Chinese, with no indication that the user can choose another language. This can violate language/locale policy when a skill imposes a specific language without user opt-in or documented regional scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.