Back to skill

Security audit

openai-tts-api

Security checks for vulnerabilities and agentic risk

Overview

This TTS skill mostly documents a real external API flow, but its setup points agents to unpinned remote instructions and enables many unrelated APIs beyond text-to-speech.

Review before installing. Use this only if you intend to route TTS prompts and your SkillBoss API key through SkillBoss, avoid sensitive or regulated text unless you have reviewed SkillBoss's terms and privacy posture, and do not let an agent follow the remote setup instruction unless you are comfortable enabling broad non-TTS SkillBoss capabilities from an unpinned external document.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Warning
Location
SKILL.md:31
Finding

Unpinned Remote Setup Instructions Expand the Skill Beyond TTS Scope

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 31-38
Vulnerability Type: Remote payload retrieval through agent-directed setup instructions
Risk Level: Medium

Vulnerable code snippet:

markdown
## Setup (One Command)

Tell your agent:

set up skillboss.co/skill.md

text

This auto-configures SkillBoss with 687 APIs — chat, image, video, audio, search, scraping, social data, email, and more.

Technical Analysis

The Skill instructs an agent to set up content referenced by skillboss.co/skill.md. Unlike the locally audited SKILL.md, this remote document is mutable and is not pinned to a version or protected by an integrity hash. Its effective instructions can therefore change after this package has been reviewed.

The advertised setup also configures 687 APIs spanning chat, scraping, social data, email, and other capabilities. Those capabilities are unrelated to the declared OpenAI TTS purpose and exceed the minimum functional scope required to submit text and receive synthesized audio.

The repository does not contain direct code that fetches or executes the remote document, so exploitation depends on the consuming agent interpreting the setup request by retrieving and following the referenced content. If it does, the external document becomes a post-review instruction channel controlled by the remote service.

Attack Path

  1. A user or agent loads this Skill to perform an OpenAI TTS request.
  2. The agent follows the recommended set up skillboss.co/skill.md instruction.
  3. The agent retrieves or interprets the externally hosted setup document.
  4. The remote document supplies setup actions that were not included in the audited package.
  5. If the remote content is compromised or changed maliciously, it can instruct the agent to invoke tools, alter configuration, request broader credentials, or enable APIs unrelated to TTS.
  6. Those instructions execute with whatever files ...[truncated 876 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the remote bootstrap instruction with complete, locally stored, auditable setup steps.
  2. Configure only the TTS endpoint and permissions needed for openai/tts-1; do not automatically enable unrelated chat, scraping, social-data, or email APIs.
  3. If remote setup content is unavoidable, pin it to an immutable version and verify a published cryptographic digest or signature before use.
  4. Require explicit user confirmation before retrieving remote instructions or making configuration changes.
  5. Clearly enumerate every action the setup process will perform, including files modified, credentials accessed, and capabilities enabled.
  6. Run setup with restricted filesystem, command-execution, and network permissions.
  7. Add a privacy notice explaining that prompts and authentication credentials are sent to SkillBoss as an intermediary.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation guidance says to use the skill whenever the user needs OpenAI TTS API, but it does not define safety boundaries, data sensitivity limits, or consent requirements for sending prompts to a third party. Overly broad trigger text can cause automatic invocation in contexts where users did not intend external transmission or use of an aggregator service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The setup and examples instruct users to send prompts and bearer-authenticated requests to api.skillboss.co, but the skill does not prominently warn that this is a third-party service handling user content and credentials. Lack of disclosure undermines informed consent and can lead to unintended sharing of sensitive prompts or metadata.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is presented as a narrowly scoped OpenAI TTS integration, but the setup text immediately expands its scope to hundreds of unrelated APIs. That mismatch can mislead users and agents into granting a credential with much broader access than expected, increasing the blast radius if the skill is invoked or the key is reused improperly.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The curl quick test transmits prompt content and a bearer token to api.skillboss.co. While this is normal API behavior, it creates a real data-sharing path to a third-party provider that is not clearly surfaced to users in the surrounding instructions.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

Quick Test

bash
curl -X POST "https://api.skillboss.co/v1/run" \
  -H "Authorization: Bearer $SKILLBOSS_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The curl quick test transmits prompt content and a bearer token to api.skillboss.co. While this is normal API behavior, it creates a real data-sharing path to a third-party provider that is not clearly surfaced to users in the surrounding instructions.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

Quick Test

bash
curl -X POST "https://api.skillboss.co/v1/run" \
  -H "Authorization: Bearer $SKILLBOSS_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The Python example sends user-supplied prompt data and an API bearer token to an external service. External transmission is expected for an API client, but in this skill it is risky because the service is a third-party gateway and the skill does not adequately disclose the data-sharing and credential-use implications.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

python
import requests

response = requests.post(
    "https://api.skillboss.co/v1/run",
    headers={"Authorization": "Bearer $SKILLBOSS_API_KEY"},
    json={

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The Python example sends user-supplied prompt data and an API bearer token to an external service. External transmission is expected for an API client, but in this skill it is risky because the service is a third-party gateway and the skill does not adequately disclose the data-sharing and credential-use implications.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

python
import requests

response = requests.post(
    "https://api.skillboss.co/v1/run",
    headers={"Authorization": "Bearer $SKILLBOSS_API_KEY"},
    json={

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
import requests

response = requests.post(
    "https://api.skillboss.co/v1/run",
    headers={"Authorization": "Bearer $SKILLBOSS_API_KEY"},
    json={
        "model": "openai/tts-1",

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

md
import requests

response = requests.post(
    "https://api.skillboss.co/v1/run",
    headers={"Authorization": "Bearer $SKILLBOSS_API_KEY"},
    json={
        "model": "openai/tts-1",

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises unrelated chat, image, video, scraping, and social-data capabilities despite claiming to be a TTS skill. This broad cross-promotion weakens scope boundaries and may cause an agent or user to treat the skill as approved for much wider data flows and actions than intended.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.