Back to skill

Security audit

meta-openai-whisper

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a generated meta-skill with no exfiltration or destructive code, but it makes broad unsupported claims about Whisper, self-verification, orchestration, and cross-session learning that users should review before installing.

Review this skill carefully before installing. It does not show evidence of credential theft, network exfiltration, or destructive actions, but it also does not provide an auditable Whisper workflow matching its claims. Treat its self-verification and self-evolution promises as unsupported unless the publisher adds concrete, bounded instructions and user controls.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding
The skill markets itself as an enhanced Whisper-derived meta-skill with self-verification, reflection, orchestration, and continuous evolution, but the file provides no concrete implementation or bounded behavior for those claims. This mismatch is dangerous because users or upstream agents may grant trust, invoke it for speech-related tasks, or rely on nonexistent safeguards, creating a false sense of assurance and enabling misuse or unsafe delegation.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The invocation guidance says to directly use this skill for the entire 'openai-whisper' domain without defining clear trigger conditions, task boundaries, or safety constraints. Overly broad routing instructions can cause inappropriate automatic invocation, task hijacking, or reliance on a skill outside its real capabilities, especially in agentic environments with dynamic tool selection.

Static analysis

No suspicious patterns detected.