Back to skill

Security audit

Voice

Security checks for vulnerabilities and agentic risk

Overview

This Telegram voice skill does what it claims, but users should understand that voice messages will be transcribed and that one Python dependency is installed without a pinned version.

Install only if you are comfortable with Telegram voice messages being transcribed automatically. Prefer using a pinned faster-whisper version in an isolated environment, and check how OpenClaw handles audio files and transcripts if the voice messages may contain sensitive information.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:51
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 51-54
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

markdown
## Requirements

- faster-whisper: `pip install faster-whisper`
- TTS already configured in OpenClaw

Technical Analysis

The documented installation command retrieves faster-whisper without pinning an audited version, verifying package hashes, using a dependency lockfile, or restricting resolution to an explicitly trusted package index. Its transitive dependencies are similarly unconstrained.

Consequently, the code installed by users may differ from the code assessed during this audit. If a future package release, transitive dependency, build dependency, or package-resolution source is compromised, installation or subsequent import and execution could run attacker-controlled code with the privileges of the user operating the agent.

No evidence indicates that the currently referenced package is malicious. The vulnerability is the mutable and insufficiently verified dependency acquisition process.

Attack Path

  1. An attacker compromises a future release, transitive dependency, build dependency, or package-resolution source used by pip.
  2. A user follows the documented pip install faster-whisper instruction.
  3. Pip resolves and downloads the compromised package because no approved version or cryptographic hash is enforced.
  4. Malicious code executes during a source-package build, dependency installation, package import, or voice transcription.
  5. The malicious code operates with the permissions and data access available to the user running the installation or agent.

Impact Assessment

Successful exploitation could permit arbitrary code execution under the installing user's account. Depending on that account's privileges and environment, the attacker could access local files, voice-message contents, Telegram-related data available to the process, con ...[truncated 182 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the mutable installation command with an exact, reviewed version pin.
  • Maintain a lockfile that fixes all transitive and build dependencies to reviewed versions.
  • Record and enforce cryptographic hashes, such as through a generated requirements file installed with pip install --require-hashes -r requirements.txt.
  • Configure pip to use an explicitly trusted package index and disable unintended additional indexes.
  • Prefer prebuilt, verified wheels where appropriate and avoid unreviewed source builds.
  • Scan locked dependencies for known vulnerabilities and review dependency changes before updating the lockfile.
  • Perform installation and transcription under a dedicated, least-privileged account or isolated environment with limited access to credentials and sensitive files.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs automatic transcription of incoming Telegram voice messages, which means user-provided audio content is processed by a speech-to-text model without any notice, consent flow, or privacy guidance. Voice messages can contain sensitive personal or confidential information, so silent processing increases privacy and compliance risk even if the transcription is performed locally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.