Back to skill

Security audit

Podcast Chaptering

Security checks for vulnerabilities and agentic risk

Overview

This podcast chaptering skill is purpose-aligned, but its API examples can expose transcript processing and filesystem actions without enough access controls.

Review before installing or using in production. Do not expose the sample API publicly as written; require authentication, bind locally by default, restrict batch jobs to a dedicated workspace, add upload and rate limits, and pin dependencies. Treat transcripts as potentially sensitive because AI mode sends transcript text to an external model provider unless you use a local model path.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:225
Finding

Unauthenticated Network-Facing Processing API

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:261
Finding

Caller-Controlled Filesystem Paths in Batch Processing Endpoint

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:225
Finding

Unbounded File Upload Buffering and JSON Processing

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:285
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

L011 使用“Use when 需要API集成、接口对接、Webhook配置、系统连接时使用”等宽泛条件来描述何时调用该技能,覆盖面过大,且没有给出明确触发词、边界或反例。这类表述容易与大量常见开发/集成场景重叠,导致技能被意外调用。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The description lists '自动发布集成:支持主流播客平台', which presents auto-publishing/platform integration as a core capability. Later, the documentation explicitly states '默认仅生成内容不自动发布', indicating the skill does not actually perform publishing by default and only supports integration into a workflow. This is an intent-level contradiction in the documentation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill describes uploading transcript files and sending transcript content to an external LLM API, but it does not clearly warn that user data may leave the local environment and be processed by a third party. In a podcast workflow, transcripts may contain unreleased content, personal data, or confidential business information, so silent external transmission creates a meaningful privacy and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

L011 明确写有“支持中文交互,无需复杂配置即开即用”,并在其他位置持续以中文作为默认交互表述,但没有说明用户可选择其他交互语言。虽然文档也提到支持多语言处理,交互语言层面的默认中文仍可能被理解为强制语言策略。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

At L291 the documentation says the AI chaptering feature requires 'OPENAI_API_KEY', matching the OpenAI client usage shown earlier. But the setup example at L300 exports 'API_KEY' instead, which contradicts the stated runtime requirement and would not satisfy the documented code path as written.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.