Back to skill

Security audit

Voice Memos

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward voice-memo transcription guide that uses a third-party API, with privacy and input-validation caveats users should understand before use.

Install only if you are comfortable sending selected voice memo audio to SenseAudio for transcription. Avoid using it for confidential, regulated, or highly personal recordings unless you have checked the provider's data handling terms, keep the API key in a secure environment variable, and confirm each file path before upload.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:46
Finding

Unrestricted Local File Upload to External Transcription Service

Content
View full analysis
Remediation
View remediation
MAX_AUDIO_SIZE: raise ValueError("Audio file exceeds the permitted size") with resolved.open("rb") as audio: response = requests.post( "https://api.senseaudio.cn/v1/audio/transcriptions", headers={"Authorization": f"Bearer {API_KEY}"}, files={"file": (resolved.name, audio)}, data={"model": "sense-asr", "response_format": "json"}, timeout=(10, 120), ) response.raise_for_status() return response.json()["text"] ``` ]]>

T08 · Insecure Dependencies

Warning
Location
SKILL.md:30
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
\ --hash=sha256: ``` All transitive dependencies must also be pinned and supplied with verified hashes for `--require-hashes` to provide complete protection. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is explicitly designed to upload user-provided audio to a third-party transcription API, but the documentation does not clearly warn users that potentially sensitive voice memo content leaves the local environment. Voice memos commonly contain personal, financial, health, or work information, so silent external transmission creates a meaningful privacy and compliance risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The code sends local audio files to an external HTTPS endpoint for transcription, which is expected for the feature but still constitutes real data exfiltration from the local environment to a third party. In the context of voice memos, the transmitted data may contain sensitive spoken content, making the external transmission security-relevant even if functionality-driven.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
import requests

def transcribe_voice_memo(audio_file):
    url = "https://api.senseaudio.cn/v1/audio/transcriptions"

    headers = {"Authorization": f"Bearer {API_KEY}"}
    files = {"file": open(audio_file, "rb")}

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill requires an external API credential but does not provide guidance on secure handling of the key or explain that use of the credential authorizes a third-party service to process uploaded audio. This increases the chance of unsafe credential practices and uninformed use of a service that can access potentially sensitive content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.