Back to skill

Security audit

Voice Note Polisher

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only voice-note polishing skill with no code execution or data access, though its routing is broad enough that users should invoke it deliberately.

Install this if you want automatic cleanup of dictated or oral Chinese notes. Be explicit about the target format and language, especially for mixed-language text, because the skill’s broad triggers may otherwise rewrite generic editing requests as voice-note cleanup.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill-level description says it should trigger whenever text appears oral or disfluent, even without an explicit request for this skill. That broad routing criterion can cause unintended activation on ordinary user messages, leading the agent to rewrite or reformat content the user did not mean to transform. In context, this is not code-execution dangerous, but it is a real prompt-routing vulnerability because it can override user intent and produce the wrong action.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The metadata states that the skill defaults to clear Chinese output whenever the text appears colloquial, even if the user did not request Chinese. This can override the user's language preference and cause unintended translation or language normalization, which is especially problematic for mixed-language or non-Chinese inputs. The impact is lower than the routing issues, but it is still a genuine behavior-safety problem because it can alter meaning and violate user expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The listed trigger phrases are common, high-frequency phrases like '帮我整理成…' and '帮我把下面内容写成…', which overlap with many generic editing requests outside the intended transcript-polishing use case. This increases the chance that the router selects this skill when a user wanted another kind of summarization, drafting, or general writing assistance. The skill context makes this more dangerous because it also strips control phrases and rewrites output directly, reducing visibility into the misrouting.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Activating the default mode on the ambiguous phrase '帮我整理一下' without any transcript-specific qualifier makes accidental routing likely. Many users use that phrase for arbitrary organization, editing, or analysis tasks, so the skill may hijack requests and force a transcript-cleanup behavior that the user did not intend. In this context, the danger is primarily integrity and UX-related: silent transformation of content and loss of task fidelity.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.