T09 · Insecure Skill Coding Practices
- Location
scripts/macos/process.sh:14- Finding
Arbitrary Command Execution Through Unsafe Evaluation of Configuration Values
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This voice-to-notes skill is coherent, but it needs review because it can run background watchers, auto-launch AI agents, download/build code, and delete original recordings.
Review before installing. Use agent_cli: none unless you explicitly want transcripts sent to another AI CLI, preserve originals or back them up before processing, avoid automatic monitoring until configured, prefer official dependency sources with pinned hashes, and inspect config.json because config values affect shell execution on macOS.
scripts/macos/process.sh:14Arbitrary Command Execution Through Unsafe Evaluation of Configuration Values
scripts/common/trigger_agent.sh:74Automatic Privileged Agent Invocation Exposes the Workflow to Transcript Prompt Injection
scripts/common/deps_manager.py:61Executable Dependencies and Models Are Downloaded Without Cryptographic Integrity Verification
scripts/common/trigger_agent.sh:136Predictable Shared Temporary Log Files Permit Data Exposure and Symlink Attacks
The skill includes uninstall behavior that stops and removes a launchd agent, but this lifecycle-management capability is not reflected in the high-level description. While not inherently malicious, undisclosed service removal and LaunchAgents modification can surprise users and affect persistence or automation on the host.
The skill includes uninstall behavior that stops and removes a launchd agent, but this lifecycle-management capability is not reflected in the high-level description. While not inherently malicious, undisclosed service removal and LaunchAgents modification can surprise users and affect persistence or automation on the host.
The skill includes uninstall behavior that stops and removes a launchd agent, but this lifecycle-management capability is not reflected in the high-level description. While not inherently malicious, undisclosed service removal and LaunchAgents modification can surprise users and affect persistence or automation on the host.
The skill includes uninstall behavior that stops and removes a launchd agent, but this lifecycle-management capability is not reflected in the high-level description. While not inherently malicious, undisclosed service removal and LaunchAgents modification can surprise users and affect persistence or automation on the host.
Referenced artifact was not completely inspected
The skill root is the `record2note/` folder containing this `SKILL.md`. All script paths are relative to that folder.
Referenced artifact was not completely inspected
The skill root is the `record2note/` folder containing this `SKILL.md`. All script paths are relative to that folder.
The generated prompt instructs the external agent to save notes, archive audio, modify metadata, update index pages, and delete both source audio and pending JSON files. This is dangerous because the agent is being granted autonomous authority over destructive filesystem actions based on untrusted transcript content and broad natural-language instructions rather than strict programmatic controls.
The script directs the agent to create and modify notes and later delete original audio and pending JSON files without any confirmation, preview, or rollback mechanism. In a recording workflow, this is especially risky because source audio may be irreplaceable, and errors by the agent or prompt misinterpretation could lead to permanent data loss.
Re-invoking PowerShell with ExecutionPolicy Bypass weakens a host security control and normalizes unrestricted script execution during file-watch events. In this skill, the child process is launched automatically when new files appear, so a local attacker who can influence the watched environment or script path gets a more permissive execution path than necessary for transcription.
The script crosses from PowerShell into bash to execute another script and passes user/config-influenced values such as the result file and agent CLI setting. This broadens the execution surface and can enable command/argument injection or unintended tool execution, especially on Windows hosts with mixed shell environments and weak validation of downstream script behavior.
The skill declares broad operational behavior involving shell execution, filesystem access, environment inspection, and network downloads, but provides no explicit tool scope or permission boundary. This is dangerous because an agent may invoke powerful capabilities implicitly, making user consent, sandboxing, and policy enforcement harder and increasing the risk of unintended system changes.
The workflow includes moving recordings to archive locations and deleting originals from the watch directory, but the user-facing description does not prominently warn about these destructive file operations. This is dangerous because users may assume processing is non-destructive and inadvertently lose originals or synced copies.
The skill describes automatic background triggering of external agent CLIs with full config and templates, but does not clearly warn that transcripts and related metadata may be passed to another process. This is dangerous because sensitive voice content, file paths, and configuration may be exposed to tools with separate trust boundaries or remote integrations without informed user consent.
Pending-file processing explicitly deletes original watch files and processed JSON files after note generation, without a clear irreversible-cleanup warning. This is dangerous because cleanup may remove the only remaining copy of source inputs or forensic artifacts needed for recovery, auditing, or reprocessing.
The code downloads binaries and models from network sources and dynamically switches to third-party mirrors such as ghfast.top and hf-mirror.com, but it does not verify checksums or signatures. This creates a substantial supply-chain risk, especially for executable artifacts and source used in builds.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
if config.get("diarization", True):
try:
subprocess.run(
["python3", "-c", "import pyannote.audio"],
capture_output=True, check=True, timeout=10
)
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
if config.get("diarization", True):
try:
subprocess.run(
["python3", "-c", "import pyannote.audio"],
capture_output=True, check=True, timeout=10
)
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
if config.get("diarization", True):
try:
subprocess.run(
["python3", "-c", "import pyannote.audio"],
capture_output=True, check=True, timeout=10
)
The dependency manager goes beyond note conversion and actively installs packages, downloads executables, and can build software from source. In the context of an agent skill, that is materially more dangerous because it allows host modification and code execution paths unrelated to the primary user task.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
return False
print(f"[record2note] Installing {formula} via Homebrew...")
print("[record2note] (This may take several minutes on first install)")
result = subprocess.run([brew, "install", formula], check=False,
timeout=600)
if result.returncode != 0:
print(f"[record2note] brew install {formula} failed.", file=sys.stderr)
The script automatically installs cmake via pip when missing, which causes unprompted code retrieval and execution from an external package index on the user's machine. Even without shell injection, this expands trust to external registries and changes the environment without explicit approval.
if not cmake_binary:
print("[record2note] cmake not found, installing via pip...")
result = subprocess.run(
[sys.executable, "-m", "pip", "install", "cmake"],
check=False, timeout=120
)
The code clones and then later builds source from a remote repository URL that may be rewritten to a third-party mirror. This enables execution of remotely supplied source code during build, which is particularly risky in an agent skill whose expected purpose is note conversion rather than software compilation.
try:
repo_url = build_github_url(f"https://github.com/{repo}", mirror_config)
print(f"[record2note] Cloning {repo}...")
result = subprocess.run(
["git", "clone", "--depth", "1", "--branch", tag, repo_url, build_dir],
check=False, timeout=300
)
This step configures a build tree for previously downloaded remote source, forming part of an automated remote-code execution chain on the local host. In context, the danger comes from executing an unverified software supply chain, not from shell injection.
cmake_build_dir = os.path.join(build_dir, "build")
os.makedirs(cmake_build_dir, exist_ok=True)
print("[record2note] Configuring build...")
result = subprocess.run(
[cmake_binary, "..", "-DCMAKE_BUILD_TYPE=Release",
"-DWHISPER_BUILD_EXAMPLES=ON"],
cwd=cmake_build_dir, check=False, timeout=120
Invoking make on cloned remote source executes the project's build instructions locally, which can run arbitrary commands embedded in build files. Because the source may come via mirror rewriting and no authenticity verification is performed, this is a meaningful supply-chain risk.
print("[record2note] Building whisper-cli (this may take a few minutes)...")
cpu_count = os.cpu_count() or 2
result = subprocess.run(
["make", f"-j{cpu_count}", "whisper-cli"],
cwd=cmake_build_dir, check=False, timeout=600
)
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
def _install_ffmpeg_port(port_path):
print("[record2note] Installing ffmpeg via MacPorts...")
print("[record2note] (This may require sudo and take several minutes)")
result = subprocess.run([port_path, "install", "ffmpeg"], check=False, timeout=600)
if result.returncode != 0:
print("[record2note] Error: port install ffmpeg failed.", file=sys.stderr)
No suspicious patterns detected.