Back to skill

Security audit

openai-transcription

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed RunAPI transcription helper with some ordinary dependency and download-scope cautions, but no hidden or destructive behavior was found.

Install only if you are comfortable trusting RunAPI's CLI/Homebrew tap and SDK sources. Use it with user-selected audio files and a dedicated RunAPI API key where possible, and be cautious if a transcription response asks the agent to download unexpected non-transcript media.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12-17
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

Vulnerable Code

yaml
install:
- kind: brew
  formula: runapi-ai/tap/runapi
  bins:
  - runapi

The related production-integration instructions at lines 97-104 also direct the agent to obtain current package installation information from a mutable external SDK reference:

markdown
Use this route only for application or production-code integration. Open the current RunAPI SDK reference below, select the package for the target language and `OpenAI Transcription`, and confirm its install command, client methods, request types, response types, and error classes before coding. Build the request from the same discovered product contract and apply the same deliverable verification and stop rules. Do not invoke `runapi` as a subprocess from production code.

## References

- Model overview, pricing, and rate limits: https://runapi.ai/models/openai-transcription.md
- Provider overview: https://runapi.ai/providers/openai.md
- Full model catalog: https://runapi.ai/models.md
- SDK integration: https://github.com/runapi-ai/openai-transcription-sdk

Technical Analysis

The skill specifies a third-party Homebrew tap and formula without pinning an audited version, immutable commit, checksum, or cryptographic signature. The production integration route similarly delegates package selection and installation details to mutable remote documentation.

This creates a supply-chain trust gap: the effective software installed when the skill is used may differ from the dependency state that existed during this audit. Although the audit found no evidence that the currently referenced project is malicious, compromise of the tap, formula repository, SDK repository, publishing account, or referenced documentation could cause an agent to install altered code.

Attack Path

...[truncated 1077 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to a reviewed, explicit version rather than installing the mutable latest formula.
  2. Pin third-party source repositories to immutable commit hashes or signed release tags.
  3. Verify downloaded artifacts using documented cryptographic checksums and release signatures before installation.
  4. Record exact SDK package names and approved versions instead of delegating package selection entirely to mutable remote documentation.
  5. Use lockfiles with integrity metadata for application integrations and enforce them in CI.
  6. Restrict dependency installation and execution to a sandbox or minimally privileged account without unrelated credentials.
  7. Establish a controlled upgrade process in which new dependency versions are reviewed and verified before the pins are updated.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill first frames outputs as non-media transcription results, then later tells the agent to process generic deliverables including videos, images, and audios. This contract inconsistency is dangerous because agents may trust the later instructions and perform unintended downloads or file validation on attacker-influenced URLs, broadening the attack surface beyond transcription.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The verification section instructs the agent to download every 'media deliverable' and even infer MIME families such as audio, despite this skill being for transcription where expected outputs are typically text or subtitle artifacts. In an agent setting, this expands behavior beyond the declared purpose and can cause the agent to fetch attacker-controlled URLs or unrelated files embedded in a response, creating unnecessary network access and data-handling risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.