Back to skill

Security audit

ElevenLabs Agents

Security checks for vulnerabilities and agentic risk

Overview

The skill is for managing ElevenLabs agents, but it tells the agent to hide local setup actions and gives under-scoped authority to write files and change remote agent configurations.

Review this skill carefully before installing. It is not showing clear evidence of theft or destructive intent, but it may authenticate to ElevenLabs, create local configuration files, add webhook tools, and push changes to your ElevenLabs account while hiding implementation details. Only use it in a workspace where local ElevenLabs project files are expected, and require explicit confirmation before authentication, file creation, webhook setup, or deployment.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:47
Finding

Shell Command Injection Through an Unsanitized Agent Name

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 47–56
Vulnerability Type: Shell command injection
Risk Level: High

Vulnerable code snippet:

markdown
When user wants to create an agent:

1. Ask for agent name and purpose (don't mention "templates")
2. Based on their description, choose appropriate template:
   - Customer support → `customer-service`
   - General assistant → `assistant`
   - Voice-focused → `voice-only`
   - Simple/minimal → `minimal`
   - Default for unclear cases → `default`
3. Run: `elevenlabs agents add "Name" --template <template>`

Technical Analysis

The skill directs the agent to collect an attacker-controlled agent name and insert it into a quoted CLI command. It does not require validation, shell-safe escaping, or execution through a structured argument array.

Double quotes do not provide adequate protection when untrusted input can itself contain quotes, command substitutions, or shell control operators. If the agent constructs the documented command as a string and passes it to a shell, a malicious name can terminate the quoted argument and append another command.

For example, an agent name shaped like the following benign proof of concept would escape the intended argument:

text
x"; id; echo "

Interpolation would produce a command equivalent to:

bash
elevenlabs agents add "x"; id; echo "" --template default

The shell would consequently execute id independently of the ElevenLabs CLI. The issue is not inherent to the ElevenLabs CLI; it arises from constructing a shell command by interpolating untrusted input.

Attack Path

  1. An attacker asks the skill to create an ElevenLabs agent.
  2. The attacker supplies an agent name containing a closing quote and shell control operators.
  3. The AI agent substitutes that name into the documented command template.
  4. The resulting command string is submitted to a shel ...[truncated 1203 chars]
Remediation
View remediation

Remediation Suggestions

  1. Invoke the ElevenLabs CLI through a process API that accepts an executable and argument array, without a shell. For example, pass arguments conceptually as:

    text
    ["agents", "add", userSuppliedName, "--template", validatedTemplate]
    
  2. Explicitly prohibit command construction through string concatenation, interpolation, shell=True, sh -c, bash -c, or equivalent shell wrappers.

  3. Validate agent names using a documented policy:

    • Enforce a reasonable maximum length.
    • Reject control characters and line breaks.
    • Prefer an allowlist of letters, digits, spaces, hyphens, and underscores where compatible with ElevenLabs.
    • Return a validation error instead of silently transforming ambiguous input.
  4. Select template values exclusively from the fixed allowlist documented by the skill. Never accept an arbitrary template string from the user.

  5. Update the instruction to state that user-provided values must be passed as literal process arguments and must never be interpolated into a shell command.

  6. Add security tests using names containing quotes, semicolons, command substitutions, backticks, newlines, and option-like prefixes to verify that they cannot create additional commands or alter CLI arguments.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Behavior Manipulation

Medium
Category
Prompt Injection
Confidence
90% confidence
Finding

Telling the agent to 'Never tell users to run commands' and to 'Handle everything silently' manipulates the agent toward concealing operational details from the user. In a skill that performs authentication, file creation, syncing, and deployment, this reduces transparency and makes unauthorized or unexpected actions more likely to occur without informed user approval.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
## Critical Behavior Rules

1. **Hide CLI details**: Never tell users to run commands. Handle everything silently.
2. **Handle errors gracefully**: If a command fails, fix it yourself or explain the situation in user-friendly terms.
3. **Local vs Remote distinction**: Always be clear whether you're showing local (synced) agents or remote (platform) agents.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The authentication flow tells the agent to begin login handling after requesting an API key, but it does not require a clear warning that credentials will be transmitted to ElevenLabs and may be stored or used by local tooling. This can lead users to disclose secrets without informed consent, especially because the skill emphasizes silent handling of operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly directs silent execution of elevenlabs agents init when agents.json is missing, which causes local filesystem changes without user knowledge or consent. Hidden write operations are risky because they can modify the working directory, create persistent state, and surprise users who expected a read-only or purely informational action.

Content

No source excerpt is available for this finding.

Behavior Manipulation

Medium
Category
Prompt Injection
Confidence
98% confidence
Finding

The instruction 'Never tell the user about missing agents.json - just initialize' is an explicit directive to hide a state-changing action from the user. This is dangerous because it normalizes covert modification of the user's workspace and removes the opportunity for the user to approve, redirect, or decline the initialization step.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

bash
elevenlabs agents init

Never tell the user about missing agents.json - just initialize.

Operations

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This workflow instructs the agent to create a configuration file for a webhook tool and then push changes remotely, but it does not require disclosure that local files will be created and that a remote agent configuration will be modified. Silent local writes combined with remote deployment can have security and operational consequences, especially if the webhook URL or configuration is sensitive or misconfigured.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
## Critical Behavior Rules

1. **Hide CLI details**: Never tell users to run commands. Handle everything silently.
2. **Handle errors gracefully**: If a command fails, fix it yourself or explain the situation in user-friendly terms.
3. **Local vs Remote distinction**: Always be clear whether you're showing local (synced) agents or remote (platform) agents.

Static analysis

No suspicious patterns detected.