Back to skill

Security audit

audiopod

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward SkillBoss audio API helper, but users should understand that supplied text, URLs, and audio are sent to SkillBoss for processing.

Install only if you are comfortable sending selected audio, media URLs, generated lyrics, text, and transcripts to SkillBoss using your API key. Avoid confidential meetings, private voice recordings, regulated data, or third-party audio unless you have permission and understand SkillBoss handling and retention terms.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (23)

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
API_BASE = "https://api.skillboss.co/v1"

def pilot(body: dict) -> dict:
    r = requests.post(
        f"{API_BASE}/pilot",
        headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
        json=body,

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

audio_url = result["data"]["result"]["audio_url"]

text

### cURL

```bash
# Generate full song

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation instructs users to base64-encode and upload local audio files for remote processing, but it does not clearly warn that potentially sensitive voice content and derived transcripts leave the local environment. This creates a privacy and consent risk, especially for meetings, recordings, or other personal audio containing PII or confidential information.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 203)May include surrounding context.

vocal_url = result["data"]["result"]["download_urls"]["vocals"]

text

### cURL

```bash
# Extract stems from URL

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 339)May include surrounding context.

segments = result["data"]["result"]["segments"]

text

### cURL

```bash
# Diarize from URL

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 454)May include surrounding context.

clean_url = result["data"]["result"]["audio_url"]

text

### cURL

```bash
# Denoise from URL

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is advertised as an audio-processing tool, but the documented Chain mode introduces broader chat-based summarization and translation behavior not reflected in the manifest. This capability expansion can let the skill process arbitrary text tasks and increases the chance of misuse, over-broad invocation, or unintended data handling beyond the declared scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Documenting a general type: "chat" capability inside an audio skill exposes functionality outside the stated purpose, creating a scope mismatch that can bypass user and platform expectations. If invoked, it may send transcript-derived or arbitrary text to a remote chat processor without users realizing the skill is no longer limited to audio transformation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The file documents a hardcoded external API endpoint used for audio processing, confirming that user-provided content is transmitted to an outside service. In this skill context, external transmission is expected functionality, but it still creates a real privacy and data-governance risk if users are not informed and sensitive audio is sent without consent.

Content

Scanner excerpt · references/stems.md (reported line 21)May include surrounding context.

API Endpoint

All requests: POST https://api.skillboss.co/v1/pilot Auth: Authorization: Bearer $SKILLBOSS_API_KEY

json

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The reference explicitly instructs sending user audio or third-party media URLs to a remote SkillBoss API, but it does not warn that content leaves the local environment or discuss privacy/consent implications. Because this skill handles potentially sensitive voice and media data, omission of an off-device transmission notice can mislead users and cause unintended disclosure of personal or copyrighted content.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

API Endpoint

All requests: POST https://api.skillboss.co/v1/pilot Auth: Authorization: Bearer $SKILLBOSS_API_KEY

json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

API Endpoint

All requests: POST https://api.skillboss.co/v1/pilot Auth: Authorization: Bearer $SKILLBOSS_API_KEY

json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

API Endpoint

All requests: POST https://api.skillboss.co/v1/pilot Auth: Authorization: Bearer $SKILLBOSS_API_KEY

json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

API Endpoint

All requests: POST https://api.skillboss.co/v1/pilot Auth: Authorization: Bearer $SKILLBOSS_API_KEY

json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

API Endpoint

All requests: POST https://api.skillboss.co/v1/pilot Auth: Authorization: Bearer $SKILLBOSS_API_KEY

json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 207)May include surrounding context.

API Endpoint

All requests: POST https://api.skillboss.co/v1/pilot Auth: Authorization: Bearer $SKILLBOSS_API_KEY

json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 213)May include surrounding context.

API Endpoint

All requests: POST https://api.skillboss.co/v1/pilot Auth: Authorization: Bearer $SKILLBOSS_API_KEY

json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 280)May include surrounding context.

API Endpoint

All requests: POST https://api.skillboss.co/v1/pilot Auth: Authorization: Bearer $SKILLBOSS_API_KEY

json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 343)May include surrounding context.

API Endpoint

All requests: POST https://api.skillboss.co/v1/pilot Auth: Authorization: Bearer $SKILLBOSS_API_KEY

json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 394)May include surrounding context.

API Endpoint

All requests: POST https://api.skillboss.co/v1/pilot Auth: Authorization: Bearer $SKILLBOSS_API_KEY

json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 458)May include surrounding context.

API Endpoint

All requests: POST https://api.skillboss.co/v1/pilot Auth: Authorization: Bearer $SKILLBOSS_API_KEY

json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 512)May include surrounding context.

API Endpoint

All requests: POST https://api.skillboss.co/v1/pilot Auth: Authorization: Bearer $SKILLBOSS_API_KEY

json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/tts.md (reported line 5)May include surrounding context.

API Endpoint

All requests: POST https://api.skillboss.co/v1/pilot Auth: Authorization: Bearer $SKILLBOSS_API_KEY

json

Static analysis

No suspicious patterns detected.