Back to skill

Security audit

Voice Memo Transcribe

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to do the advertised Voice Memos transcription workflow, but it asks for broad Mac disk access and uses insecure handling for private transcript content.

Install only if you are comfortable giving the terminal broad access to protected Mac data. Prefer exporting selected recordings manually or using a dedicated restricted environment, install and pin dependencies before granting extra access, review transcripts before saving them to Notes/iCloud, and delete any temporary transcript files after use.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:74
Finding

Unpinned Runtime Dependency Installation

Content
View full analysis
" [options] ``` The installed package is subsequently imported by `scripts/transcribe.py:48-54`: ```python try: from faster_whisper import WhisperModel except ImportError: print("ERROR: faster-whisper not installed.", file=sys.stderr) print("Run with: uv run --with faster-whisper python3 scripts/transcribe.py ...", file=sys.stderr) return 1 ``` ### Technical Analysis The documented command asks `uv` to resolve and execute `faster-whisper` without specifying an audited version or enforcing an integrity hash. Consequently, package behavior may change between executions. If the package or one of its transitive dependencies is compromised upstream, malicious package code may execute when the package is imported or used. The risk is amplified because the instructions also ask the user to grant Full Disk Access to the terminal. Resolving dependencies in the same privileged execution context gives third-party package code access to the terminal process's effective permissions. The audit did not find evidence that `faster-whisper` itself is malicious. The vulnerability is the absence of reproducible dependency pinning and integrity verification. ### Attack Path 1. An attacker compromises a future release of `faster-whisper` or one of its transitive dependencies. 2. The user runs the documented `uv run --with faster-whisper ...` command. 3. `uv` resolves and installs the compromised dependency because no version or hash is pinned. 4. `scripts/transcribe.py` imports `WhisperModel` from the installed package. 5. Attacker-controlled initialization or runtime code executes with the terminal process's permissions. 6. If the terminal has Full Disk Access, the malicious dependency may read or modify unrelated p ...[truncated 414 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:103
Finding

Predictable Shared Temporary File Exposes Transcript Content

Content
View full analysis
" set noteTitle to "" set noteBody to do shell script "cat /tmp/note_content.txt" ``` Cleanup is only presented as an advisory instruction at `SKILL.md:139`: ```markdown - Clean up `/tmp/note_content.txt` after use ``` ### Technical Analysis The workflow stores potentially sensitive transcript and summary content at the fixed path `/tmp/note_content.txt`. A predictable filename in a shared temporary directory introduces several local security problems: - Another local process may observe and read the file while it exists. - An attacker may pre-create the path as a symbolic link, causing the Python process to follow that link when opening the file for writing. - Another process may replace or modify the file between the Python write and the later `cat` operation, creating a time-of-check/time-of-use race. - Because cleanup is advisory rather than guaranteed, transcript data may remain in `/tmp` after execution. - The code does not explicitly establish restrictive file permissions. The fixed file is used as a trust boundary between Python and AppleScript without validating that it is still the same regular file created by the workflow. ### Attack Path One possible note-tampering path is: 1. A local attacker monitors `/tmp/note_content.txt`. 2. The legitimate workflow writes the intended transcript to that path. 3. Before AppleScript executes `cat /tmp/note_content.txt`, the attacker replaces or modifies the file. 4. AppleScript reads the attacker-controll ...[truncated 1145 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:25
Finding

Terminal-Wide Full Disk Access Expands the Privilege Boundary

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a full Voice Memos-to-text-to-Apple Notes pipeline using faster-whisper transcription on macOS. The actual code does something materially different: it inspects an m4a container for an already embedded transcript atom and prints that text. This is not merely an implementation detail difference; it changes the core capability from transcribing audio to extracting existing metadata. The code also lacks any Apple Notes interaction, Voice Memos database access, iCloud handling, or workflow orchestration described in the declaration.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This code chunk's primary behavior is read-only enumeration of Voice Memo entries from CloudRecordings.db. While accessing the Voice Memos database is consistent with part of the declared workflow, the core advertised functionality—transcribing recordings into text and saving/organizing them in Apple Notes—is absent. The code also does not process audio files, invoke any transcription model, or interact with Apple Notes. Therefore the description materially overstates and misrepresents what this code actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description promises a broader Apple ecosystem workflow centered on Voice Memos ingestion, organization, and saving to Apple Notes. The actual code chunk does not implement that workflow. It simply transcribes an arbitrary audio file provided on the command line using faster-whisper and optionally saves plain text to a file. The auto device detection and faster-whisper usage do align with part of the description, but the core claimed behavior involving Voice Memos, Apple Notes, iCloud synchronization, and content organization is absent. This is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Requesting Full Disk Access to reach the Voice Memos database materially expands the blast radius of the terminal or agent, exposing far more than the intended recordings if the environment is compromised or commands are misused. The skill tells users to grant this privilege but does not clearly warn that it can expose unrelated personal files, application data, and synced content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill describes automatically saving transcript content into Apple Notes and syncing it through iCloud without a prominent warning that potentially sensitive audio-derived text will be persisted and replicated across devices and cloud storage. Voice memos often contain private conversations, so silent or poorly explained syncing increases the chance of unintended disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.