Back to skill

Security audit

Record2Note

Security checks for vulnerabilities and agentic risk

Overview

This voice-to-notes skill is coherent, but it needs review because it can run background watchers, auto-launch AI agents, download/build code, and delete original recordings.

Review before installing. Use agent_cli: none unless you explicitly want transcripts sent to another AI CLI, preserve originals or back them up before processing, avoid automatic monitoring until configured, prefer official dependency sources with pinned hashes, and inspect config.json because config values affect shell execution on macOS.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/macos/process.sh:14
Finding

Arbitrary Command Execution Through Unsafe Evaluation of Configuration Values

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
scripts/common/trigger_agent.sh:74
Finding

Automatic Privileged Agent Invocation Exposes the Workflow to Transcript Prompt Injection

Content
View full analysis
.md 7. Archive the original audio from the `source` path into the `{archive_dir}/YYYY-MM-DD/` directory 8. Update the note frontmatter `source` field to the archived path 9. Delete the original audio file from th ...[truncated 3090 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/common/deps_manager.py:61
Finding

Executable Dependencies and Models Are Downloaded Without Cryptographic Integrity Verification

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/common/trigger_agent.sh:136
Finding

Predictable Shared Temporary Log Files Permit Data Exposure and Symlink Attacks

Content
View full analysis
> /tmp/record2note-agent.log 2>&1 & ;; claude) echo "[record2note] Triggering claude to process: $PENDING_FILE" nohup claude -p --append-system-prompt "You are an assistant that processes voice transcription notes." "$PROMPT" >> /tmp/record2note-agent.log 2>&1 & ;; codex) echo "[record2note] Triggering codex to process: $PENDING_FILE" nohup codex "$PROMPT" >> /tmp/record2note-agent.log 2>&1 & ;; gemini) echo "[record2note] Triggering gemini to process: $PENDING_FILE" nohup gemini "$PROMPT" >> /tmp/record2note-agent.log 2>&1 & ;; esac ``` ```xml StandardOutPath /tmp/record2note.log StandardErrorPath /tmp/record2note.err ``` ### Technical Analysis The Skill writes logs to fixed names under `/tmp`, a shared and attacker-influenced namespace on typical Unix-like systems. The code does not create the files securely, reject symbolic links, or explicitly enforce private permissions. A local attacker may pre-create one of these paths as a symbolic link to another file writable by the victim. When the Agent or LaunchAgent appends output, the write follows the link. Depending on the system's protections and the user's umask, another local user may also be able to read logs containing filenames, paths, transcript-derived output, errors, or Agent responses. ...[truncated 981 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (71)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill includes uninstall behavior that stops and removes a launchd agent, but this lifecycle-management capability is not reflected in the high-level description. While not inherently malicious, undisclosed service removal and LaunchAgents modification can surprise users and affect persistence or automation on the host.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill includes uninstall behavior that stops and removes a launchd agent, but this lifecycle-management capability is not reflected in the high-level description. While not inherently malicious, undisclosed service removal and LaunchAgents modification can surprise users and affect persistence or automation on the host.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill includes uninstall behavior that stops and removes a launchd agent, but this lifecycle-management capability is not reflected in the high-level description. While not inherently malicious, undisclosed service removal and LaunchAgents modification can surprise users and affect persistence or automation on the host.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill includes uninstall behavior that stops and removes a launchd agent, but this lifecycle-management capability is not reflected in the high-level description. While not inherently malicious, undisclosed service removal and LaunchAgents modification can surprise users and affect persistence or automation on the host.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
The skill root is the `record2note/` folder containing this `SKILL.md`. All script paths are relative to that folder.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
The skill root is the `record2note/` folder containing this `SKILL.md`. All script paths are relative to that folder.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The generated prompt instructs the external agent to save notes, archive audio, modify metadata, update index pages, and delete both source audio and pending JSON files. This is dangerous because the agent is being granted autonomous authority over destructive filesystem actions based on untrusted transcript content and broad natural-language instructions rather than strict programmatic controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script directs the agent to create and modify notes and later delete original audio and pending JSON files without any confirmation, preview, or rollback mechanism. In a recording workflow, this is especially risky because source audio may be irreplaceable, and errors by the agent or prompt misinterpretation could lead to permanent data loss.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

Re-invoking PowerShell with ExecutionPolicy Bypass weakens a host security control and normalizes unrestricted script execution during file-watch events. In this skill, the child process is launched automatically when new files appear, so a local attacker who can influence the watched environment or script path gets a more permissive execution path than necessary for transcription.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script crosses from PowerShell into bash to execute another script and passes user/config-influenced values such as the result file and agent CLI setting. This broadens the execution surface and can enable command/argument injection or unintended tool execution, especially on Windows hosts with mixed shell environments and weak validation of downstream script behavior.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
98% confidence
Finding

The skill declares broad operational behavior involving shell execution, filesystem access, environment inspection, and network downloads, but provides no explicit tool scope or permission boundary. This is dangerous because an agent may invoke powerful capabilities implicitly, making user consent, sandboxing, and policy enforcement harder and increasing the risk of unintended system changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The workflow includes moving recordings to archive locations and deleting originals from the watch directory, but the user-facing description does not prominently warn about these destructive file operations. This is dangerous because users may assume processing is non-destructive and inadvertently lose originals or synced copies.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes automatic background triggering of external agent CLIs with full config and templates, but does not clearly warn that transcripts and related metadata may be passed to another process. This is dangerous because sensitive voice content, file paths, and configuration may be exposed to tools with separate trust boundaries or remote integrations without informed user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Pending-file processing explicitly deletes original watch files and processed JSON files after note generation, without a clear irreversible-cleanup warning. This is dangerous because cleanup may remove the only remaining copy of source inputs or forensic artifacts needed for recovery, auditing, or reprocessing.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code downloads binaries and models from network sources and dynamically switches to third-party mirrors such as ghfast.top and hf-mirror.com, but it does not verify checksums or signatures. This creates a substantial supply-chain risk, especially for executable artifacts and source used in builds.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/common/deps_manager.py (reported line 312)May include surrounding context.

python
if config.get("diarization", True):
        try:
            subprocess.run(
                ["python3", "-c", "import pyannote.audio"],
                capture_output=True, check=True, timeout=10
            )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/common/deps_manager.py (reported line 744)May include surrounding context.

python
if config.get("diarization", True):
        try:
            subprocess.run(
                ["python3", "-c", "import pyannote.audio"],
                capture_output=True, check=True, timeout=10
            )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/common/deps_manager.py (reported line 755)May include surrounding context.

python
if config.get("diarization", True):
        try:
            subprocess.run(
                ["python3", "-c", "import pyannote.audio"],
                capture_output=True, check=True, timeout=10
            )

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The dependency manager goes beyond note conversion and actively installs packages, downloads executables, and can build software from source. In the context of an agent skill, that is materially more dangerous because it allows host modification and code execution paths unrelated to the primary user task.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/common/deps_manager.py (reported line 354)May include surrounding context.

python
return False
    print(f"[record2note] Installing {formula} via Homebrew...")
    print("[record2note] (This may take several minutes on first install)")
    result = subprocess.run([brew, "install", formula], check=False,
                           timeout=600)
    if result.returncode != 0:
        print(f"[record2note] brew install {formula} failed.", file=sys.stderr)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
86% confidence
Finding

The script automatically installs cmake via pip when missing, which causes unprompted code retrieval and execution from an external package index on the user's machine. Even without shell injection, this expands trust to external registries and changes the environment without explicit approval.

Content

Scanner excerpt · scripts/common/deps_manager.py (reported line 389)May include surrounding context.

python
if not cmake_binary:
        print("[record2note] cmake not found, installing via pip...")
        result = subprocess.run(
            [sys.executable, "-m", "pip", "install", "cmake"],
            check=False, timeout=120
        )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
92% confidence
Finding

The code clones and then later builds source from a remote repository URL that may be rewritten to a third-party mirror. This enables execution of remotely supplied source code during build, which is particularly risky in an agent skill whose expected purpose is note conversion rather than software compilation.

Content

Scanner excerpt · scripts/common/deps_manager.py (reported line 407)May include surrounding context.

python
try:
        repo_url = build_github_url(f"https://github.com/{repo}", mirror_config)
        print(f"[record2note] Cloning {repo}...")
        result = subprocess.run(
            ["git", "clone", "--depth", "1", "--branch", tag, repo_url, build_dir],
            check=False, timeout=300
        )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
90% confidence
Finding

This step configures a build tree for previously downloaded remote source, forming part of an automated remote-code execution chain on the local host. In context, the danger comes from executing an unverified software supply chain, not from shell injection.

Content

Scanner excerpt · scripts/common/deps_manager.py (reported line 418)May include surrounding context.

python
cmake_build_dir = os.path.join(build_dir, "build")
        os.makedirs(cmake_build_dir, exist_ok=True)
        print("[record2note] Configuring build...")
        result = subprocess.run(
            [cmake_binary, "..", "-DCMAKE_BUILD_TYPE=Release",
             "-DWHISPER_BUILD_EXAMPLES=ON"],
            cwd=cmake_build_dir, check=False, timeout=120

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
93% confidence
Finding

Invoking make on cloned remote source executes the project's build instructions locally, which can run arbitrary commands embedded in build files. Because the source may come via mirror rewriting and no authenticity verification is performed, this is a meaningful supply-chain risk.

Content

Scanner excerpt · scripts/common/deps_manager.py (reported line 429)May include surrounding context.

python
print("[record2note] Building whisper-cli (this may take a few minutes)...")
        cpu_count = os.cpu_count() or 2
        result = subprocess.run(
            ["make", f"-j{cpu_count}", "whisper-cli"],
            cwd=cmake_build_dir, check=False, timeout=600
        )

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/common/deps_manager.py (reported line 609)May include surrounding context.

python
def _install_ffmpeg_port(port_path):
    print("[record2note] Installing ffmpeg via MacPorts...")
    print("[record2note] (This may require sudo and take several minutes)")
    result = subprocess.run([port_path, "install", "ffmpeg"], check=False, timeout=600)
    if result.returncode != 0:
        print("[record2note] Error: port install ffmpeg failed.", file=sys.stderr)

Static analysis

No suspicious patterns detected.