T09 · Insecure Skill Coding Practices
- Location
acoustic.py:37- Finding
Sensitive microphone audio transmitted over unauthenticated plaintext HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill has a coherent acoustic-classification purpose, but it captures microphone audio, sends it over unauthenticated HTTP, overstates its privacy protections, and suggests broader camera, alarm, and memory actions.
Review carefully before installing. Use only with explicit user consent, a trusted and authenticated local edge service, and a network you control; do not rely on the stated 'absolute' LAN or memory-erasure guarantees, and avoid letting agents automatically trigger cameras, alarms, smart-home changes, or memory logging from this skill's output.
acoustic.py:37Sensitive microphone audio transmitted over unauthenticated plaintext HTTP
acoustic.py:24LAN destination validation does not enforce the documented RFC 1918 boundary
acoustic.py:52Deletion of Python references does not securely erase recorded audio
SKILL.md:9Third-party Python dependencies are installed without version or integrity pinning
The skill performs network communication by sending recorded audio to an HTTP endpoint, but the declared permissions do not reflect that capability. Undeclared network access is dangerous because it defeats user and platform expectations about data flow, especially for microphone-derived content that is privacy-sensitive even on a LAN.
The description does not prominently warn users that the skill captures live environmental audio and sends it to another host, even if that host is on a private LAN. The repeated privacy-assurance language ('Ephemeral Privacy', 'Strict LAN Isolation', 'verified private IP') can create a misleading sense of safety and downplay the sensitivity of microphone surveillance and local-network exfiltration.
The skill’s activation scope is broad and underspecified for a capability that performs live environmental audio capture and network transmission. Because it lacks strict trigger boundaries, session constraints, and narrowly defined invocation conditions, an agent could invoke ambient listening more often than the user expects, increasing the risk of covert surveillance or over-collection of sensitive conversations.
The skill transmits base64-encoded microphone audio to an HTTP endpoint using urllib, which is an external transmission of sensitive sensor data. The context makes this more dangerous because the code claims 'strict LAN isolation' and 'ephemeral privacy,' yet still sends raw audio over unauthenticated, unencrypted HTTP to any private/loopback IP, including potentially attacker-controlled local hosts.
data = json.dumps(payload).encode('utf-8')
try:
with urllib.request.urlopen(req, data=data, timeout=15.0) as response:
return json.loads(response.read().decode('utf-8'))
except Exception as e:
return {"error": f"Edge Brain Connection Failed: {str(e)}. Please check if Edge Brain is running at {self.edge_url}"}
The code recommends escalating an acoustic event into camera or radar surveillance, which materially broadens monitoring beyond the stated acoustic-perception role. This is dangerous because a low-confidence or misclassified sound can trigger more invasive sensing modalities without explicit user authorization.
The skill claims LAN-only acoustic classification with strong privacy guarantees, but also recommends logging music preferences and smart-home automation actions unrelated to the core acoustic detection purpose. This is dangerous because it expands use of sensed data beyond the user-expected purpose, creating privacy and scope-creep risks.
The code suggests logging user preferences to memory when music is detected, which is unrelated to the advertised privacy-preserving acoustic radar function. This is dangerous because it converts transient environmental sensing into behavioral profiling, undermining the claimed ephemeral/privacy-preserving design.
The file consistently embeds bilingual Chinese/English strings in comments, CLI descriptions, errors, and output fields. Because the skill imposes a specific locale presentation style without any user choice or documented locale justification, it may violate language/locale policy requirements.
No suspicious patterns detected.