Back to skill

Security audit

Open Utter (Meeting Bot)

Security checks for vulnerabilities and agentic risk

Overview

OpenUtter is a coherent meeting-transcription bot, but it needs Review because it handles Google sessions and sensitive meeting data while also containing a confirmed shell-command injection risk.

Install only if you are comfortable with a bot joining meetings, storing transcripts, taking screenshots, and saving a reusable Google session on disk. Use it only for meetings where recording/transcription is authorized, avoid untrusted channel or target values, prefer pinned local dependencies, and protect or delete ~/.openutter/auth.json when not needed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/utter-join.ts:44
Finding

Shell Command Injection Through Messaging Arguments

Content
View full analysis
= 0 ? args[channelIdx + 1] : undefined; const targetIdx = args.indexOf("--target"); const target = targetIdx >= 0 ? args[targetIdx + 1] : undefined; ``` ### Technical Analysis `execSync()` receives a single interpolated command string, causing Node.js to execute it through a system shell. The attacker-controlled `channel` value is interpolated without quoting or validation, allowing shell metacharacters such as `;`, `|`, redirection operators, backticks, or `$()` to alter the command. Although `target`, `message`, and `mediaPath` are passed through `JSON.stringify()`, JSON string quoting is not sh ...[truncated 1737 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/utter-auth.ts:124
Finding

Google Session Material Is Stored Without Enforced Restrictive Permissions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:47
Finding

Unpinned Packages May Be Downloaded and Executed Through npx

Content
View full analysis
--target " ``` Additional documented invocations use the same pattern: ```bash npx tsx skills/openutter/scripts/utter-transcript.ts ``` ```bash npx tsx skills/openutter/scripts/utter-screenshot.ts ``` ```bash npx tsx skills/openutter/scripts/utter-auth.ts ``` ### Technical Analysis The documented workflow executes `tsx` and `playwright-core` through `npx` without specifying exact versions or providing a project lockfile in the audited directory. When the requested executable is not already available in a trusted local installation, `npx` may resolve and download a package from the configured npm registry and immediately execute it. The reviewed source therefore does not fully determine the code that runs. Registry compromise, account takeover, altered package releases, malicious registry configuration, or unexpected dependency updates could introduce code that was not included in this audit. This is a supply-chain weakness rather than evidence that the currently named packages are malicious. ### Attack Path 1. A user or agent follows `SKILL.md` and runs one of the documented `npx` commands. 2. The requested executable is absent from the trusted local dependency tree, or local resolution otherwise falls back to the package registry. 3. `npx` resolves an unpinned package version using the current npm configuration. 4. A compromised, replaced, or unexpectedly modified package is downloaded. 5. Package lifecycle code or the resolved executable runs with the user's privile ...[truncated 788 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (40)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The top-level description also does not reflect the separate screenshot-control and local process/PID coordination mechanisms. This hidden complexity matters because it introduces additional local attack surface and side effects unrelated to simple meeting join/transcript capture.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The top-level description also does not reflect the separate screenshot-control and local process/PID coordination mechanisms. This hidden complexity matters because it introduces additional local attack surface and side effects unrelated to simple meeting join/transcript capture.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The top-level description also does not reflect the separate screenshot-control and local process/PID coordination mechanisms. This hidden complexity matters because it introduces additional local attack surface and side effects unrelated to simple meeting join/transcript capture.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill captures and stores live meeting captions/transcripts on disk but does not present a clear privacy warning or consent requirement near the feature description. Because meeting captions often contain sensitive personal, business, or regulated information, silent persistence materially increases privacy, compliance, and insider-risk exposure.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/utter-auth.ts (reported line 15)May include surrounding context.

ts
* On subsequent runs, utter-join.ts loads auth.json so the bot joins as an
 * authenticated Google user — no guest admission needed.
 *
 * No client_secret.json or OAuth setup required.
 */

import { existsSync, mkdirSync, readFileSync, writeFileSync } from "node:fs";

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The SIGUSR1 handler enables on-demand screenshots of the live meeting page, creating a covert capture mechanism unrelated to caption transcription. In a meeting bot, this is especially sensitive because visuals may include participant video, chat, names, and shared screens containing confidential material.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The bot captures screenshots of the meeting state and shares them through an external messaging channel, which exceeds the stated transcript purpose and can expose sensitive meeting content. Because this occurs automatically on success/failure paths, it creates a privacy and data-exfiltration risk even when users may only expect caption logging.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The core function automatically captures and stores live speech transcripts from a meeting with no consent checks, sensitivity filtering, or retention guardrails. In this skill context, that is dangerous because meetings often contain confidential business, personal, or regulated information, and the transcript file is persisted to disk for later access or misuse.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The launch command executes npx tsx without a pinned version, which can pull or resolve an unexpected package version at runtime. In an automation skill that joins meetings and handles transcripts/screenshots, this expands supply-chain risk because arbitrary dependency changes could alter behavior or execute attacker-controlled code.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger guidance for transcript retrieval is broad enough to overlap with ordinary conversational phrases about meetings. In this skill's context, that can cause the agent to fetch and summarize stored meeting transcripts unexpectedly, exposing sensitive meeting content without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

This transcript retrieval command uses unpinned npx tsx, creating the same supply-chain and runtime drift risk as the join flow. Because the script reads meeting transcript data, compromise here could expose sensitive content or alter what is reported back to the user.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The screenshot command relies on npx tsx without version pinning, allowing dependency substitution or unreviewed version changes at execution time. Since screenshots may contain sensitive meeting content, compromise could leak data or run unintended code in the agent environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The authentication flow runs via unpinned npx tsx, which is more sensitive than other uses because it handles Google sign-in and session persistence. A malicious or unexpected resolved package version could capture credentials, cookies, or auth artifacts.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

This later transcript command again executes unpinned npx tsx, repeating the same supply-chain exposure. Repeated dynamic execution increases attack surface across multiple sensitive actions in the skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script persists Playwright storage state containing Google authentication cookies and local storage to ~/.openutter/auth.json for reuse. That creates a reusable authenticated session artifact on disk; if the file is read by another local user, malware, backups, or logs, an attacker may hijack the Google session without needing the password or MFA.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill can send arbitrary progress messages and media files to an external openclaw channel, which is outside the stated purpose of joining meetings and capturing captions. In this context, that extra exfiltration path increases the chance of leaking meeting metadata, screenshots, or operational state to destinations the meeting participants did not consent to.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/utter-join.ts (reported line 948)May include surrounding context.

ts
const {
    meetUrl,
    headed = false,
    noAuth = false,
    noCamera = true,
    noMic = true,
    verbose = false,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The browser context is configured with a fixed English-language user agent, and the injected stealth script also hard-codes navigator.languages to ["en-US", "en"]. This imposes a specific locale behavior without offering user choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill captures meeting captions into transcript files and also takes/shares screenshots without presenting any clear privacy notice or consent workflow in the code. In a meeting context, silent recording/retention materially increases legal, compliance, and confidentiality risk because participants may not realize their speech and visuals are being stored.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The stealth init script overrides navigator.languages to always return English locales. This is a natural-language policy concern because it forces a specific language/locale setting regardless of user preference.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script explicitly adds screenshot-capture capability to a skill described as a transcript-only Google Meet bot. Screenshots can capture participant identities, shared screens, chats, or other sensitive visual content far beyond captions, creating a privacy and scope-expansion risk that is not clearly disclosed by the manifest.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code provides on-demand retrieval of a screenshot path after signaling a running bot, enabling ad hoc visual capture unrelated to the stated transcript-capture purpose. In a meeting context, that increases the risk of covert collection of sensitive content from presentations, participant video, or chat, especially because the trigger is a local signal rather than an explicit in-meeting consent action.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/utter-join.ts:51