Back to skill

Security audit

S2-SP-OS Acoustic Radar

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent acoustic-classification purpose, but it captures microphone audio, sends it over unauthenticated HTTP, overstates its privacy protections, and suggests broader camera, alarm, and memory actions.

Review carefully before installing. Use only with explicit user consent, a trusted and authenticated local edge service, and a network you control; do not rely on the stated 'absolute' LAN or memory-erasure guarantees, and avoid letting agents automatically trigger cameras, alarms, smart-home changes, or memory logging from this skill's output.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
acoustic.py:37
Finding

Sensitive microphone audio transmitted over unauthenticated plaintext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
acoustic.py:24
Finding

LAN destination validation does not enforce the documented RFC 1918 boundary

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
acoustic.py:52
Finding

Deletion of Python references does not securely erase recorded audio

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:9
Finding

Third-party Python dependencies are installed without version or integrity pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Lp1

High
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill performs network communication by sending recorded audio to an HTTP endpoint, but the declared permissions do not reflect that capability. Undeclared network access is dangerous because it defeats user and platform expectations about data flow, especially for microphone-derived content that is privacy-sensitive even on a LAN.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description does not prominently warn users that the skill captures live environmental audio and sends it to another host, even if that host is on a private LAN. The repeated privacy-assurance language ('Ephemeral Privacy', 'Strict LAN Isolation', 'verified private IP') can create a misleading sense of safety and downplay the sensitivity of microphone surveillance and local-network exfiltration.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill’s activation scope is broad and underspecified for a capability that performs live environmental audio capture and network transmission. Because it lacks strict trigger boundaries, session constraints, and narrowly defined invocation conditions, an agent could invoke ambient listening more often than the user expects, increasing the risk of covert surveillance or over-collection of sensitive conversations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The skill transmits base64-encoded microphone audio to an HTTP endpoint using urllib, which is an external transmission of sensitive sensor data. The context makes this more dangerous because the code claims 'strict LAN isolation' and 'ephemeral privacy,' yet still sends raw audio over unauthenticated, unencrypted HTTP to any private/loopback IP, including potentially attacker-controlled local hosts.

Content

Scanner excerpt · acoustic.py (reported line 91)May include surrounding context.

python
data = json.dumps(payload).encode('utf-8')
        
        try:
            with urllib.request.urlopen(req, data=data, timeout=15.0) as response:
                return json.loads(response.read().decode('utf-8'))
        except Exception as e:
            return {"error": f"Edge Brain Connection Failed: {str(e)}. Please check if Edge Brain is running at {self.edge_url}"}

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code recommends escalating an acoustic event into camera or radar surveillance, which materially broadens monitoring beyond the stated acoustic-perception role. This is dangerous because a low-confidence or misclassified sound can trigger more invasive sensing modalities without explicit user authorization.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill claims LAN-only acoustic classification with strong privacy guarantees, but also recommends logging music preferences and smart-home automation actions unrelated to the core acoustic detection purpose. This is dangerous because it expands use of sensed data beyond the user-expected purpose, creating privacy and scope-creep risks.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code suggests logging user preferences to memory when music is detected, which is unrelated to the advertised privacy-preserving acoustic radar function. This is dangerous because it converts transient environmental sensing into behavioral profiling, undermining the claimed ephemeral/privacy-preserving design.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file consistently embeds bilingual Chinese/English strings in comments, CLI descriptions, errors, and output fields. Because the skill imposes a specific locale presentation style without any user choice or documented locale justification, it may violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.