Back to skill

Security audit

openclaw-feishu-voice-free

Security checks for vulnerabilities and agentic risk

Overview

The skill's voice-chat purpose is understandable, but it ships overly broad unauthenticated services, root persistence instructions, unsafe file handling, and hardcoded credentials that need review before use.

Review this skill carefully before installing. Replace and rotate all embedded credentials, bind services to 127.0.0.1, add authentication and request limits, run under a dedicated unprivileged account, avoid the root systemd units as written, use only trusted voice clone files, and require consent for any voice cloning or automatic voice-message processing.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (9)

T09 · Insecure Skill Coding Practices

Error
Location
openclaw.json:102
Finding

Hardcoded Operational Credentials and Access Tokens

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
openclaw.json:53
Finding

Shell Command Injection Through Unescaped Media Path Interpolation

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/server/whisper-server.py:40
Finding

Unauthenticated Network-Wide ASR Service Reads Attacker-Selected Local Files

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/server/tts-base-server.py:36
Finding

Unauthenticated TTS Endpoint Allows Arbitrary Filesystem Writes

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/server/tts-base-server-openai.py:91
Finding

Unauthenticated Model Inference Services Permit Resource Exhaustion

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:454
Finding

Persistent Root Services Exceed the Skill's Minimum Privilege Requirements

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/tools/tts-base.py:80
Finding

Remote Mode Uploads Voice Biometrics and Transcripts to Arbitrary Plaintext Endpoints

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/server/tts-base-server-openai.py:423
Finding

Unsafe Deserialization of Voice Clone Files with torch.load

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
setup.sh:64
Finding

Unpinned Dependencies and Model Revisions Create Supply-Chain Risk

Content
View full analysis
/dev/null || echo " (whisper optional, using transformers instead)" ``` The documentation also downloads mutable model repositories without pinning a reviewed commit or revision: ```bash huggingface-cli download openai/whisper-large-v3-turbo \ --local-dir /root/.openclaw/models/whisper/whisper-large-v3-turbo huggingface-cli download Qwen/Qwen3-TTS-12Hz-1.7B-Base \ --local-dir /root/.openclaw/models/Qwen3-TTS/Qwen3-TTS-12Hz-1.7B-Base ``` ### Technical Analysis The installer resolves the latest available versions of multiple packages and performs no hash verification. Package installation can execute build or installation code. A compromised upstream release, dependency account, package index, or transitive dependency can therefore change the code executed by future installations without changes to this Skill. Model downloads are similarly not tied to reviewed immutable revisions. ### Attack Path 1. An attacker compromises an upstream package, dependency account, model repository, or distribution channel. 2. A user runs `setup.sh` or the documented model-download commands. 3. Package resolution selects the compromised mutable release or model revision. 4. Malicious installation or runtime code executes within the virtual en ...[truncated 400 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (53)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The configuration embeds multiple live secrets directly in the file, including Feishu app secrets, a gateway auth token, skill API keys, and a Tavily API key. Storing credentials in a skill/config file creates immediate secret exposure risk through source control leaks, backups, logs, local file disclosure, or unintended sharing, and these values could be used to impersonate services or access connected systems.

Content

No source excerpt is available for this finding.

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
85% confidence
Finding

os.system() and os exec-family calls run shell commands with the process's full privileges, enabling arbitrary command execution.

Content

Scanner excerpt · scripts/tools/tts-base.py (reported line 43)May include surrounding context.

python
# Always use venv if available and not already active
if not os.environ.get("QWEN_TTS_VENV_ACTIVE") and VENV_PYTHON.exists():
    os.environ["QWEN_TTS_VENV_ACTIVE"] = "1"
    os.execv(str(VENV_PYTHON), [str(VENV_PYTHON)] + sys.argv)

# Check for remote mode
REMOTE_URL = os.environ.get("QWEN_TTS_REMOTE")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is documented to automatically transcribe incoming Feishu voice messages, locally download/process them, and synthesize replies, but it provides no privacy notice or user-consent guidance. This is risky because users may not realize their audio is being stored and transformed, creating privacy, compliance, and surveillance concerns even if processing is local.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README promotes cloning arbitrary voices and custom voice embeddings without any consent, impersonation, or abuse warning. In a voice-chat skill, this materially increases misuse risk because operators may deploy impersonation-capable features without guardrails, policy checks, or user disclosure.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation advertises the skill as 'completely offline' and '无需任何云端 API', but the setup explicitly requires downloading models from Hugging Face and even allows repo IDs that can trigger automatic remote downloads at runtime. This is misleading security documentation: operators may deploy it under the false assumption that no network access or supply-chain exposure exists, reducing scrutiny of outbound access and model provenance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill promotes arbitrary voice cloning without any warning about consent, impersonation, or misuse risks. In a messaging/voice-reply context, this can facilitate deceptive impersonation, privacy abuse, or unauthorized use of another person's voice, especially if users are encouraged to clone '任意人声'.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 61)May include surrounding context.

md
source venv/bin/activate

# 启动 Whisper ASR 服务(端口 8001)
nohup python scripts/server/whisper-server.py --port 8001 > /tmp/whisper-server.log 2>&1 &

# 启动 Qwen3-TTS 服务(端口 8000,使用 OpenAI 兼容 API)
nohup python scripts/server/tts-base-server-openai.py --port 8000 --clone voice_embedings/huopo_kexin.pt > /tmp/tts-server.log 2>&1 &

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 64)May include surrounding context.

md
source venv/bin/activate

# 启动 Whisper ASR 服务(端口 8001)
nohup python scripts/server/whisper-server.py --port 8001 > /tmp/whisper-server.log 2>&1 &

# 启动 Qwen3-TTS 服务(端口 8000,使用 OpenAI 兼容 API)
nohup python scripts/server/tts-base-server-openai.py --port 8000 --clone voice_embedings/huopo_kexin.pt > /tmp/tts-server.log 2>&1 &

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 390)May include surrounding context.

md
source venv/bin/activate

# 启动 Whisper ASR 服务(端口 8001)
nohup python scripts/server/whisper-server.py --port 8001 > /tmp/whisper-server.log 2>&1 &

# 启动 Qwen3-TTS 服务(端口 8000,使用 OpenAI 兼容 API)
nohup python scripts/server/tts-base-server-openai.py --port 8000 --clone voice_embedings/huopo_kexin.pt > /tmp/tts-server.log 2>&1 &

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 393)May include surrounding context.

md
source venv/bin/activate

# 启动 Whisper ASR 服务(端口 8001)
nohup python scripts/server/whisper-server.py --port 8001 > /tmp/whisper-server.log 2>&1 &

# 启动 Qwen3-TTS 服务(端口 8000,使用 OpenAI 兼容 API)
nohup python scripts/server/tts-base-server-openai.py --port 8000 --clone voice_embedings/huopo_kexin.pt > /tmp/tts-server.log 2>&1 &

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

md
source venv/bin/activate

# 启动 Whisper ASR 服务(端口 8001)
nohup python scripts/server/whisper-server.py --port 8001 > /tmp/whisper-server.log 2>&1 &

# 启动 Qwen3-TTS 服务(端口 8000,使用 OpenAI 兼容 API)
nohup python scripts/server/tts-base-server-openai.py --port 8000 --clone voice_embedings/huopo_kexin.pt > /tmp/tts-server.log 2>&1 &

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

md
source venv/bin/activate

# 启动 Whisper ASR 服务(端口 8001)
nohup python scripts/server/whisper-server.py --port 8001 > /tmp/whisper-server.log 2>&1 &

# 启动 Qwen3-TTS 服务(端口 8000,使用 OpenAI 兼容 API)
nohup python scripts/server/tts-base-server-openai.py --port 8000 --clone voice_embedings/huopo_kexin.pt > /tmp/tts-server.log 2>&1 &

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 390)May include surrounding context.

md
source venv/bin/activate

# 启动 Whisper ASR 服务(端口 8001)
nohup python scripts/server/whisper-server.py --port 8001 > /tmp/whisper-server.log 2>&1 &

# 启动 Qwen3-TTS 服务(端口 8000,使用 OpenAI 兼容 API)
nohup python scripts/server/tts-base-server-openai.py --port 8000 --clone voice_embedings/huopo_kexin.pt > /tmp/tts-server.log 2>&1 &

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 393)May include surrounding context.

md
source venv/bin/activate

# 启动 Whisper ASR 服务(端口 8001)
nohup python scripts/server/whisper-server.py --port 8001 > /tmp/whisper-server.log 2>&1 &

# 启动 Qwen3-TTS 服务(端口 8000,使用 OpenAI 兼容 API)
nohup python scripts/server/tts-base-server-openai.py --port 8000 --clone voice_embedings/huopo_kexin.pt > /tmp/tts-server.log 2>&1 &

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · setup.sh (reported line 105)May include surrounding context.

sh
source venv/bin/activate

# 启动 Whisper ASR 服务(端口 8001)
nohup python scripts/server/whisper-server.py --port 8001 > /tmp/whisper-server.log 2>&1 &

# 启动 Qwen3-TTS 服务(端口 8000,使用 OpenAI 兼容 API)
nohup python scripts/server/tts-base-server-openai.py --port 8000 --clone voice_embedings/huopo_kexin.pt > /tmp/tts-server.log 2>&1 &

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · setup.sh (reported line 108)May include surrounding context.

sh
source venv/bin/activate

# 启动 Whisper ASR 服务(端口 8001)
nohup python scripts/server/whisper-server.py --port 8001 > /tmp/whisper-server.log 2>&1 &

# 启动 Qwen3-TTS 服务(端口 8000,使用 OpenAI 兼容 API)
nohup python scripts/server/tts-base-server-openai.py --port 8000 --clone voice_embedings/huopo_kexin.pt > /tmp/tts-server.log 2>&1 &

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 402)May include surrounding context.

bash
# 检查 Whisper 服务
curl http://localhost:8001/

# 检查 TTS 服务
curl http://localhost:8000/

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 402)May include surrounding context.

bash
# 检查 Whisper 服务
curl http://localhost:8001/

# 检查 TTS 服务
curl http://localhost:8000/

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 499)May include surrounding context.

启用并启动服务

bash
sudo systemctl daemon-reload
sudo systemctl enable openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl start openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl status openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 500)May include surrounding context.

启用并启动服务

bash
sudo systemctl daemon-reload
sudo systemctl enable openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl start openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl status openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 501)May include surrounding context.

启用并启动服务

bash
sudo systemctl daemon-reload
sudo systemctl enable openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl start openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl status openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 502)May include surrounding context.

启用并启动服务

bash
sudo systemctl daemon-reload
sudo systemctl enable openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl start openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl status openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 499)May include surrounding context.

启用并启动服务

bash
sudo systemctl daemon-reload
sudo systemctl enable openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl start openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl status openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 500)May include surrounding context.

启用并启动服务

bash
sudo systemctl daemon-reload
sudo systemctl enable openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl start openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl status openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 501)May include surrounding context.

启用并启动服务

bash
sudo systemctl daemon-reload
sudo systemctl enable openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl start openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl status openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts

Static analysis

No suspicious patterns detected.