Back to skill

Security audit

PodSips Podcast Search

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed PodSips API helper for podcast transcript search, with manageable privacy and consent considerations around external queries and podcast-request submissions.

Install only if you are comfortable sending podcast searches, episode identifiers, and any missing-podcast names or RSS URLs to PodSips, with search processing involving third-party embedding/vector infrastructure as documented. Treat PODSIPS_API_KEY as a secret, watch credit costs for transcript retrieval, and ask for explicit confirmation before submitting a missing-podcast request.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (16)

External Transmission

Medium
Category
Data Exfiltration
Content
## Important

- All requests require the `PODSIPS_API_KEY` environment variable. Pass it as `Authorization: Bearer $PODSIPS_API_KEY`.
- Base URL: `https://api.podsips.com/public/v1`
- All responses are JSON.
- Credit costs are deducted per request. Most endpoints cost 1 credit. Full transcripts cost 5 credits. Podcast requests are free.
- If the user does not have a PodSips API key, follow the steps in the **Getting an API Key** section below to walk them through setup.
Confidence
50% confidence
Finding
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

External Transmission

Medium
Category
Data Exfiltration
Content
## Important

- All requests require the `PODSIPS_API_KEY` environment variable. Pass it as `Authorization: Bearer $PODSIPS_API_KEY`.
- Base URL: `https://api.podsips.com/public/v1`
- All responses are JSON.
- Credit costs are deducted per request. Most endpoints cost 1 credit. Full transcripts cost 5 credits. Podcast requests are free.
- If the user does not have a PodSips API key, follow the steps in the **Getting an API Key** section below to walk them through setup.
Confidence
50% confidence
Finding
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

External Transmission

Medium
Category
Data Exfiltration
Content
## Important

- All requests require the `PODSIPS_API_KEY` environment variable. Pass it as `Authorization: Bearer $PODSIPS_API_KEY`.
- Base URL: `https://api.podsips.com/public/v1`
- All responses are JSON.
- Credit costs are deducted per request. Most endpoints cost 1 credit. Full transcripts cost 5 credits. Podcast requests are free.
- If the user does not have a PodSips API key, follow the steps in the **Getting an API Key** section below to walk them through setup.
Confidence
50% confidence
Finding
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

External Transmission

Medium
Category
Data Exfiltration
Content
## Important

- All requests require the `PODSIPS_API_KEY` environment variable. Pass it as `Authorization: Bearer $PODSIPS_API_KEY`.
- Base URL: `https://api.podsips.com/public/v1`
- All responses are JSON.
- Credit costs are deducted per request. Most endpoints cost 1 credit. Full transcripts cost 5 credits. Podcast requests are free.
- If the user does not have a PodSips API key, follow the steps in the **Getting an API Key** section below to walk them through setup.
Confidence
50% confidence
Finding
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

External Transmission

Medium
Category
Data Exfiltration
Content
## Important

- All requests require the `PODSIPS_API_KEY` environment variable. Pass it as `Authorization: Bearer $PODSIPS_API_KEY`.
- Base URL: `https://api.podsips.com/public/v1`
- All responses are JSON.
- Credit costs are deducted per request. Most endpoints cost 1 credit. Full transcripts cost 5 credits. Podcast requests are free.
- If the user does not have a PodSips API key, follow the steps in the **Getting an API Key** section below to walk them through setup.
Confidence
50% confidence
Finding
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

External Transmission

Medium
Category
Data Exfiltration
Content
## Important

- All requests require the `PODSIPS_API_KEY` environment variable. Pass it as `Authorization: Bearer $PODSIPS_API_KEY`.
- Base URL: `https://api.podsips.com/public/v1`
- All responses are JSON.
- Credit costs are deducted per request. Most endpoints cost 1 credit. Full transcripts cost 5 credits. Podcast requests are free.
- If the user does not have a PodSips API key, follow the steps in the **Getting an API Key** section below to walk them through setup.
Confidence
50% confidence
Finding
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

External Transmission

Medium
Category
Data Exfiltration
Content
## Important

- All requests require the `PODSIPS_API_KEY` environment variable. Pass it as `Authorization: Bearer $PODSIPS_API_KEY`.
- Base URL: `https://api.podsips.com/public/v1`
- All responses are JSON.
- Credit costs are deducted per request. Most endpoints cost 1 credit. Full transcripts cost 5 credits. Podcast requests are free.
- If the user does not have a PodSips API key, follow the steps in the **Getting an API Key** section below to walk them through setup.
Confidence
50% confidence
Finding
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

External Transmission

Medium
Category
Data Exfiltration
Content
## Important

- All requests require the `PODSIPS_API_KEY` environment variable. Pass it as `Authorization: Bearer $PODSIPS_API_KEY`.
- Base URL: `https://api.podsips.com/public/v1`
- All responses are JSON.
- Credit costs are deducted per request. Most endpoints cost 1 credit. Full transcripts cost 5 credits. Podcast requests are free.
- If the user does not have a PodSips API key, follow the steps in the **Getting an API Key** section below to walk them through setup.
Confidence
50% confidence
Finding
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

External Transmission

Medium
Category
Data Exfiltration
Content
## Important

- All requests require the `PODSIPS_API_KEY` environment variable. Pass it as `Authorization: Bearer $PODSIPS_API_KEY`.
- Base URL: `https://api.podsips.com/public/v1`
- All responses are JSON.
- Credit costs are deducted per request. Most endpoints cost 1 credit. Full transcripts cost 5 credits. Podcast requests are free.
- If the user does not have a PodSips API key, follow the steps in the **Getting an API Key** section below to walk them through setup.
Confidence
50% confidence
Finding
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill is presented as a search/retrieval tool, but it also includes a state-changing POST operation that submits podcast-addition requests to the remote service. Even though the action is low-risk and free, it can cause unintended external side effects if invoked without clear user intent and informed consent.

External Transmission

Medium
Category
Data Exfiltration
Content
If the user's desired podcast is not in the database, submit a request to add it. This is free and does not consume credits.

```bash
curl -s -X POST -H "Authorization: Bearer $PODSIPS_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"podcast_name": "The Podcast Name", "rss_url": "https://feeds.example.com/podcast.xml"}' \
  "https://api.podsips.com/public/v1/podcast-requests" | jq .
Confidence
92% confidence
Finding
This POST request transmits user-provided podcast metadata to an external service and changes remote state by creating a podcast request. In context, the behavior is expected product functionality, but it still has security relevance because it can disclose data externally and perform actions on behalf of the user.

External Transmission

Medium
Category
Data Exfiltration
Content
curl -s -X POST -H "Authorization: Bearer $PODSIPS_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"podcast_name": "The Podcast Name", "rss_url": "https://feeds.example.com/podcast.xml"}' \
  "https://api.podsips.com/public/v1/podcast-requests" | jq .
```

**Parameters:**
Confidence
90% confidence
Finding
This example shows a state-changing POST with a JSON body containing podcast metadata sent to an external service. In context, it is legitimate product behavior, but it is more dangerous than the read-only endpoints because it can create persistent remote records and transmit user-supplied data.

External Transmission

Medium
Category
Data Exfiltration
Content
## Base URL

```
https://api.podsips.com/public/v1
```

## Authentication
Confidence
86% confidence
Finding
The skill is designed to call an external API at api.podsips.com, so external transmission is expected in context; however, it still represents a real data-exposure boundary because user prompts, identifiers, and retrieved content leave the local environment. The main risk is privacy and data-governance exposure if the skill is used with sensitive inputs without adequate disclosure or controls.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The documentation explicitly states that search queries are embedded using OpenAI's text-embedding-3-small model, which means user-entered search text is transmitted beyond the immediate PodSips service boundary to a third-party provider. Failing to warn users of this data flow is a real privacy and transparency issue, especially if users may submit sensitive research topics, names, or confidential content in search queries.

Missing User Warnings

Low
Confidence
80% confidence
Finding
The skill sends user queries, podcast identifiers, and potentially requested RSS URLs to an external API without clearly warning that user-supplied content leaves the local environment. This can create privacy and compliance issues when users search for sensitive topics or proprietary research targets.

Missing User Warnings

Low
Confidence
88% confidence
Finding
The setup instructions tell users to export a live API key directly in the shell but do not warn about exposure risks such as shell history, shared terminals, screenshots, or logs. This increases the chance of accidental credential disclosure and unauthorized API use.