Back to skill

Security audit

Ntriq X402 Audio Intel

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed paid audio transcription API wrapper, but users should treat submitted audio as sent to a third-party service.

Before using it, assume any audio URL or base64 audio you provide will be processed by the ntriq x402 service and may include personal or confidential speech. Use non-sensitive audio unless you trust the provider's privacy and retention practices, and confirm the $0.05 USDC x402 charge before each call.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs users to send either an audio URL or base64-encoded audio to a remote HTTPS endpoint, but it does not clearly warn that potentially sensitive voice content will leave the local environment and be processed by a third-party service. Audio often contains personal, confidential, or regulated information, so omission of an explicit transmission/privacy warning can lead users to expose sensitive data without informed consent.

Static analysis

No suspicious patterns detected.