T09 · Insecure Skill Coding Practices
- Location
scripts/transcribe.py:160- Finding
Local Absolute File Path Disclosed to the Transcription Provider
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This transcription skill mostly matches its purpose, but it bundles unrelated agent permissions and under-discloses sensitive audio upload behavior.
Review before installing. Use it only if you are comfortable sending audio and file-path metadata to iFLYTEK/XFYUN, remove the bundled .claude/settings.local.json before use, and treat the skill as MP3-only despite the broader advertised formats.
scripts/transcribe.py:160Local Absolute File Path Disclosed to the Transcription Provider
.claude/settings.local.json:3Bundled Agent Configuration Grants Unnecessary Host Filesystem and Command Permissions
The skill advertises broader functionality than it appears to provide, including WAV/PCM support and automatic language detection, while the described implementation behavior is MP3-specific and lacks real autodetection. This mismatch can cause users to provide unexpected inputs or assume privacy and processing behavior that is not actually implemented, undermining safe and informed use.
The skill documentation indicates capabilities that involve environment variables, network access, and file writing, but it does not declare any explicit tool scope or permission boundary. This weakens reviewability and can lead to overbroad execution in hosting environments, increasing the chance of unintended data access or exfiltration when handling user audio and API secrets.
The skill handles potentially sensitive audio but does not clearly warn users that recordings are uploaded to a third-party transcription provider. In this context, missing disclosure is dangerous because users may submit meetings, legal, medical, or customer-service audio without understanding that confidential content leaves the local environment.
The changelog states 'Support for 202+ Chinese dialects,' which is a natural-language locale constraint. In this manifest there is no accompanying opt-in, language choice, or explanation that the skill is intentionally region-specific, so it may violate the policy against forcing a specific language or locale without user consent or justification.
The script uploads local audio content to a third-party transcription service automatically, but provides no explicit consent prompt, warning, or privacy notice at the point of transmission. In the context of a general-purpose agent skill, users may provide sensitive recordings without realizing they are being sent off-platform, creating confidentiality and compliance risk.
The transcription task is created with default language set to "zh_cn" and accent set to "mandarin", and the CLI mirrors those defaults. This imposes a specific language/locale behavior unless the user overrides it, which can violate locale-choice policy when no explicit opt-in is obtained.
The manifest describes transcription of WAV, PCM, and MP3 audio files, implying multi-format support. In the actual transcription workflow, the code checks the file extension and raises an exception unless it is exactly '.mp3', so WAV and PCM inputs are not supported as claimed.
Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.
if args.output:
output_path = Path(args.output)
if args.output_format == "json":
output_path.write_text(
json.dumps(result, ensure_ascii=False, indent=2),
encoding='utf-8'
)
Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.
encoding='utf-8'
)
else:
output_path.write_text(text, encoding='utf-8')
print(f"\nSaved to: {args.output}")
except Exception as e:
The file presents significant portions of user-facing instructions and FAQ content only in Chinese, while other sections are in English, without stating that the skill is intended for Chinese-speaking users or offering a language preference. This can violate language/locale policy expectations when users are not given an explicit opt-in or justification for the enforced locale.
When --no-poll is used, the script prints instructions telling the user to run the script with '--action=query --task-id=...'. However, the argument parser defines neither an action selector nor a task-id parameter, so the documented follow-up command cannot work.
No suspicious patterns detected.