Back to skill

Security audit

播客

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a podcast chaptering helper, but it asks for broad read/write/command access while describing wider media tasks and unenforced safety limits.

Review this skill before installing. It does not show malicious code or persistence, but it grants broad local file and command capability for a loosely scoped media workflow. Use it only in a constrained workspace with podcast files you intend to process, and do not rely on its claimed command whitelist unless the platform enforces one separately.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The skill’s declared purpose is podcast chaptering and show-note generation, but the description broadens scope to video processing, audio editing, media conversion, and voice generation without corresponding boundaries or implementation detail. This mismatch can cause unsafe over-invocation, user confusion, and accidental routing of unrelated media tasks to a skill that also exposes read/write/exec capabilities.

Intent-Code Divergence

Medium
Confidence
80% confidence
Finding
The skill advertises audio generation even though its stated core function is analysis/generation of chapters, highlights, and show notes from existing audio or transcripts. This capability inflation can mislead agents into invoking the skill for broader media generation tasks, increasing exposure to file handling and exec paths that are unnecessary for the intended use case.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The document claims command execution is confined to a safe sandbox and whitelist, yet the skill only declares a generic exec tool and provides no enforceable restriction mechanism. In a skill with exec access, undocumented or purely declarative safety claims are dangerous because users or orchestrators may trust protections that do not actually exist, enabling arbitrary command execution or unsafe file/system access.

Vague Triggers

Medium
Confidence
87% confidence
Finding
An overly broad activation description makes it unclear when the skill should be selected, especially because it mentions multiple adjacent media tasks beyond podcast chaptering. In an agent ecosystem, ambiguous triggering can lead to inappropriate invocation of a skill with read/write/exec permissions, expanding attack surface and increasing the chance of unintended actions on user content.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.