Back to skill

Security audit

Whisper v1转录专业版

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a transcription helper, but its activation scope and remote API guidance are broader than its stated purpose warrants.

Install only if you intend to use it for audio transcription workflows. Keep its use scoped to known audio directories, review commands before running package installs or batch jobs, and do not expose the FastAPI service beyond trusted networks unless you add authentication, HTTPS, retention limits, and log scrubbing.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger condition is excessively broad, effectively saying to use the skill whenever AI model calls, dialogue, agent orchestration, or LLM apps are involved. In an agent environment with read/exec/write tools, vague activation criteria can cause the skill to run outside intended audio-transcription contexts, increasing the chance of unintended file access, command execution, or inappropriate routing of user tasks.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill documents remote API-based transcription and file upload handling but does not prominently warn about privacy, retention, logging, or sensitive-audio handling. In enterprise contexts, users may expose confidential meetings, personal data, or regulated content through service deployment or remote invocation without informed consent or safeguards.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.