Back to skill

Security audit

Voicenotes

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Voicenotes sync skill, but users should protect the API token and avoid syncing private transcripts into shared or untrusted folders.

Install only if you are comfortable giving the skill a Voicenotes API token and storing transcripts, summaries, tags, and note metadata as local markdown files. Use a private output directory, keep the token out of logs and dotfiles, and rotate the token if it is exposed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/sync-to-markdown.sh:58
Finding

Symbolic-Link File Overwrite in Markdown Synchronization

Content
View full analysis
"$FILEPATH" << EOF ``` ### Technical Analysis The output directory can be selected through either the `VOICENOTES_OUTPUT_DIR` environment variable or the `--output-dir` argument. The script then writes generated Markdown using ordinary shell redirection. Shell redirection follows an existing symbolic link at `FILEPATH`. The script does not verify that: - The output directory is trusted and not writable by another user. - The destination is a regular file rather than a symbolic link. - The canonical destination remains inside the intended output directory. - The destination is owned by the current user. - File creation uses no-follow or exclusive-create protections. The generated filename is derived from a note's date and sanitized title. If an attacker can predict that filename and create a symbolic link in the selected output directory, the subsequent redirection will truncate and replace the symlink target. ### Attack Path 1. The victim configures the Skill to write into a shared or attacker-writable output directory. 2. The attacker predicts a generated filename from a note date and title, or observes a filename from an earlier synchronization. 3. The attacker creates that filename as a symbolic link pointing to another file writable by the victim: ```bash ln -s /path/to/victim-writable-target shared-output/2024-01-15-Note-Title.md ``` 4. The victim runs: ```bash ./scripts/sync-to-markdown.sh --output-dir shared-outpu ...[truncated 1066 chars]
Remediation
View remediation
&2 exit 1 fi ``` 2. Require the output directory to be a real, trusted directory and validate its canonical path: ```bash OUTPUT_DIR=$(realpath -- "$OUTPUT_DIR") [[ -d "$OUTPUT_DIR" ]] || exit 1 ``` 3. Do not use shared or untrusted writable directories. Create a private directory with restrictive permissions: ```bash mkdir -p -- "$OUTPUT_DIR" chmod 700 -- "$OUTPUT_DIR" ``` 4. Create output through a securely generated temporary file in the validated destination directory: ```bash TMPFILE=$(mktemp --tmpdir="$OUTPUT_DIR" '.voicenotes.XXXXXX') || exit 1 chmod 600 "$TMPFILE" ``` 5. Write the complete Markdown document to the temporary file, verify that the final destination is not a symbolic link, and then perform an atomic rename. 6. For robust no-follow protection, use a helper that opens the destination with operating-system protections such as `O_NOFOLLOW` and, where appropriate, `O_EXCL`. A separate pre-write symlink check alone can be vulnerable to a time-of-check/time-of-use race. 7. Refuse operation when the destination directory is writable by untrusted users unless an explicit unsafe override is provided. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The skill requires a bearer-style access token that grants access to user recordings, transcripts, summaries, and possibly signed audio URLs. If the token is exposed, an attacker could impersonate the user against the Voicenotes API and retrieve or sync highly sensitive personal content.

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
## Setup

1. Get access token from: https://voicenotes.com/app?obsidian=true#settings
2. Set environment variable: `export VOICENOTES_TOKEN="your-token-here"`

## Quick Start

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents shell-based operations but does not declare any explicit tool scope or allowed tools. In an agent environment, this weakens policy boundaries and can let the skill invoke broader shell capabilities than users or the platform may expect, increasing the chance of unintended file or network actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The setup instructions tell users to obtain and export an access token but do not warn that it is a sensitive credential that must be protected. Users may accidentally paste it into logs, shell history, shared terminals, screenshots, or commit it into dotfiles, enabling unauthorized access to their Voicenotes data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation encourages syncing transcripts and AI summaries into markdown files without warning that these notes may contain highly sensitive personal or business information. This can lead users to persist private audio-derived content into a local workspace that may be indexed, committed, shared, or read by other tools.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/fetch-notes.sh (reported line 33)May include surrounding context.

sh
fi

# Fetch notes (POST method)
curl -s \
  -X POST \
  -H "Authorization: Bearer ${VOICENOTES_TOKEN}" \
  -H "X-API-KEY: ${VOICENOTES_TOKEN}" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
set -e

API_BASE="https://api.voicenotes.com/api/integrations/obsidian-sync"

if [ -z "$VOICENOTES_TOKEN" ]; then
  echo "Error: VOICENOTES_TOKEN environment variable not set" >&2

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/fetch-notes.sh (reported line 8)May include surrounding context.

sh
set -e

API_BASE="https://api.voicenotes.com/api/integrations/obsidian-sync"

if [ -z "$VOICENOTES_TOKEN" ]; then
  echo "Error: VOICENOTES_TOKEN environment variable not set" >&2

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/get-user.sh (reported line 7)May include surrounding context.

sh
set -e

API_BASE="https://api.voicenotes.com/api/integrations/obsidian-sync"

if [ -z "$VOICENOTES_TOKEN" ]; then
  echo "Error: VOICENOTES_TOKEN environment variable not set" >&2

Static analysis

No suspicious patterns detected.