Back to skill

Security audit

ifly-speed-transcription

Security checks for vulnerabilities and agentic risk

Overview

This transcription skill mostly matches its purpose, but it bundles unrelated agent permissions and under-discloses sensitive audio upload behavior.

Review before installing. Use it only if you are comfortable sending audio and file-path metadata to iFLYTEK/XFYUN, remove the bundled .claude/settings.local.json before use, and treat the skill as MP3-only despite the broader advertised formats.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Note
Location
scripts/transcribe.py:160
Finding

Local Absolute File Path Disclosed to the Transcription Provider

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Note
Location
.claude/settings.local.json:3
Finding

Bundled Agent Configuration Grants Unnecessary Host Filesystem and Command Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill advertises broader functionality than it appears to provide, including WAV/PCM support and automatic language detection, while the described implementation behavior is MP3-specific and lacks real autodetection. This mismatch can cause users to provide unexpected inputs or assume privacy and processing behavior that is not actually implemented, undermining safe and informed use.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documentation indicates capabilities that involve environment variables, network access, and file writing, but it does not declare any explicit tool scope or permission boundary. This weakens reviewability and can lead to overbroad execution in hosting environments, increasing the chance of unintended data access or exfiltration when handling user audio and API secrets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill handles potentially sensitive audio but does not clearly warn users that recordings are uploaded to a third-party transcription provider. In this context, missing disclosure is dangerous because users may submit meetings, legal, medical, or customer-service audio without understanding that confidential content leaves the local environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The changelog states 'Support for 202+ Chinese dialects,' which is a natural-language locale constraint. In this manifest there is no accompanying opt-in, language choice, or explanation that the skill is intentionally region-specific, so it may violate the policy against forcing a specific language or locale without user consent or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script uploads local audio content to a third-party transcription service automatically, but provides no explicit consent prompt, warning, or privacy notice at the point of transmission. In the context of a general-purpose agent skill, users may provide sensitive recordings without realizing they are being sent off-platform, creating confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The transcription task is created with default language set to "zh_cn" and accent set to "mandarin", and the CLI mirrors those defaults. This imposes a specific language/locale behavior unless the user overrides it, which can violate locale-choice policy when no explicit opt-in is obtained.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes transcription of WAV, PCM, and MP3 audio files, implying multi-format support. In the actual transcription workflow, the code checks the file extension and raises an exception unless it is exactly '.mp3', so WAV and PCM inputs are not supported as claimed.

Content

No source excerpt is available for this finding.

Tainted flow: 'result' from requests.post (line 366, network input) → pathlib.Path.write_text (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/transcribe.py (reported line 588)May include surrounding context.

python
if args.output:
                output_path = Path(args.output)
                if args.output_format == "json":
                    output_path.write_text(
                        json.dumps(result, ensure_ascii=False, indent=2),
                        encoding='utf-8'
                    )

Tainted flow: 'text' from requests.post (line 577, network input) → pathlib.Path.write_text (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/transcribe.py (reported line 593)May include surrounding context.

python
encoding='utf-8'
                    )
                else:
                    output_path.write_text(text, encoding='utf-8')
                print(f"\nSaved to: {args.output}")

    except Exception as e:

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file presents significant portions of user-facing instructions and FAQ content only in Chinese, while other sections are in English, without stating that the skill is intended for Chinese-speaking users or offering a language preference. This can violate language/locale policy expectations when users are not given an explicit opt-in or justification for the enforced locale.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

When --no-poll is used, the script prints instructions telling the user to run the script with '--action=query --task-id=...'. However, the argument parser defines neither an action selector nor a task-id parameter, so the documented follow-up command cannot work.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.