Back to skill

Security audit

Audio Upload Aioz Stream

Security checks for vulnerabilities and agentic risk

Overview

This skill uploads user-selected audio and metadata to AIOZ Stream as advertised, with no hidden persistence or unrelated behavior found.

Install only if you intend to send the selected audio file, title, tags, metadata, and AIOZ Stream API keys to the AIOZ Stream endpoint. Confirm the exact file and metadata before upload, avoid copyrighted or sensitive recordings unless you have rights to share them, and check whether the custom upload's public setting matches your intent.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to upload local audio files and associated metadata to a third-party service but does not prominently warn users that their local content and metadata will leave the local environment. In an agent setting with `read`, `write`, and `exec` tools, missing disclosure can lead users to unintentionally transmit sensitive recordings, embedded metadata, or copyrighted/private material to an external API.

Static analysis

No suspicious patterns detected.