Back to skill

Security audit

asr

Security checks for vulnerabilities and agentic risk

Overview

This is a cloud transcription skill, but its URL handling is too broad and could upload unintended local or internal data to the transcription provider.

Review before installing. Use this only if you are comfortable sending selected audio, filenames, and downloaded URL contents to SkillBoss. Do not give it sensitive recordings, private/internal URLs, localhost URLs, cloud metadata URLs, or very large files unless the publisher adds URL validation, media and size limits, JSON-safe request construction, and clearer data-handling disclosure.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/asr.sh:43
Finding

Unrestricted URL Retrieval Can Disclose Local or Internal Data

Content
View full analysis
OR --file " rm -f "$TMPFILE" "$TMPREQ" exit 1 fi AUDIO_B64=$(base64 "$TMPFILE" | tr -d '\n') rm -f "$TMPFILE" cat > "$TMPREQ" <
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/asr.sh:59
Finding

Unescaped User-Controlled Values Permit JSON Request Injection

Content
View full analysis
"$TMPREQ" <
Remediation
View remediation
"$TMPREQ" ``` Additional hardening should include: - Validate `--language` against an explicit list or strict ISO language-code syntax. - Normalize filenames and remove control characters if the original filename is not required. - Validate the generated JSON before transmission. - Reject missing option values instead of allowing a subsequent flag or empty argument to become the value. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/asr.sh:43
Finding

Unbounded Download and Base64 Processing Enable Resource Exhaustion

Content
View full analysis
OR --file " rm -f "$TMPFILE" "$TMPREQ" exit 1 fi AUDIO_B64=$(base64 "$TMPFILE" | tr -d '\n') rm -f "$TMPFILE" cat > "$TMPREQ" <
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly supports sending either a URL or a local file to a third-party ASR service, but the documentation does not warn users that local media contents and referenced remote resources will be transmitted off-host. This can cause unintentional disclosure of sensitive audio, embedded personal data, or internal-only URLs in automated agent workflows where users may assume processing is local.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest declares an external API credential (SKILLBOSS_API_KEY) and describes cloud-based audio transcription, but it does not warn users that their audio may be transmitted to a third-party service for processing. This creates a meaningful privacy and consent risk because users may provide sensitive recordings without clear disclosure that data leaves the local environment and is handled by an external provider.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/asr.sh (reported line 4)May include surrounding context.

sh
#!/usr/bin/env bash

# ASR CLI Wrapper powered by SkillBoss API Hub
# STT endpoint: https://api.skillboss.co/v1/pilot

API_BASE="https://api.skillboss.co/v1"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/asr.sh (reported line 6)May include surrounding context.

sh
#!/usr/bin/env bash

# ASR CLI Wrapper powered by SkillBoss API Hub
# STT endpoint: https://api.skillboss.co/v1/pilot

API_BASE="https://api.skillboss.co/v1"

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script will fetch any user-supplied URL and upload the retrieved content to a third-party API, creating a server-side data transfer capability that can be abused to access internal or sensitive resources if the environment running the skill has privileged network access. Even though this appears intended to support remote audio transcription, unrestricted URL fetching expands the trust boundary and can expose local-network services or unexpected data to exfiltration.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This line performs the actual transmission of collected audio data and filename metadata to an external service using an API key, which is a real data egress point. In the context of an ASR skill this may be functional, but it is still security-relevant because sensitive audio can leave the local environment and be processed by a third party.

Content

Scanner excerpt · scripts/asr.sh (reported line 71)May include surrounding context.

sh
}
EOF

        curl -s -X POST "$API_BASE/pilot" \
            -H "Authorization: Bearer $SKILLBOSS_API_KEY" \
            -H "Content-Type: application/json" \
            -d @"$TMPREQ"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill transmits user-provided audio and metadata to an external API but does not provide an explicit privacy or upload warning at the point of use. In an agent skill context, this matters because users may assume local processing, while the script actually exfiltrates potentially sensitive speech content to a third party.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation states that STT is synchronous and that results are returned immediately, yet the code accepts flags commonly associated with asynchronous or streaming behavior without implementing them. This is an active mismatch between documented behavior and code interface because users are led to believe these options are meaningful when they are discarded.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.