Back to skill

Security audit

Super-Transcribe — Unified Speech-to-Text

Security checks for vulnerabilities and agentic risk

Overview

This transcription skill is not clearly malicious, but it needs Review because it can silently process voice messages, fetch arbitrary URLs or RSS feeds, and install or upgrade unpinned packages at runtime.

Install only after reviewing the setup behavior. Avoid using URL/RSS transcription on untrusted links, do not let it process third-party recordings without consent, prefer explicit setup over runtime auto-install, and avoid the optional curl-to-shell uv installer. Treat generated HTML transcripts as untrusted until metadata escaping is fixed.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
setup.sh:169
Finding

Unverified Remote Installer Piped Directly to a Shell

Content
View full analysis
/dev/null; then ok "uv found (fast package installer)" else info "uv not found — will use pip (slower installs)" info "Install uv for faster setup: curl -LsSf https://astral.sh/uv/install.sh | sh" fi ``` ### Technical Analysis The setup script recommends downloading mutable content from an external URL and piping it directly into `sh`. Although the project only prints this command rather than executing it automatically, it presents the command as an installation instruction likely to be copied and run by users. The downloaded script is not pinned to a reviewed version and is not validated using a cryptographic checksum or signature. Consequently, the code ultimately executed can differ from the code that existed when this Skill was audited. HTTPS protects the connection in transit but does not protect against compromise of the hosting service, publication pipeline, domain, or vendor account. Installing `uv` is optional because the setup already falls back to `pip`. Direct remote shell execution therefore exceeds the minimum behavior necessary for transcription. ### Attack Path 1. An attacker compromises the remote installation endpoint, its publication pipeline, or another component trusted to serve `https://astral.sh/uv/install.sh`. 2. The attacker replaces the expected installer with a malicious shell payload. 3. A user runs `setup.sh` and receives the displayed `curl | sh` recommendation. 4. The user copies and executes the recommended command. 5. `curl` retrieves the current attacker-controlled payload and passes it directly to `sh`. 6. The payload executes with all permissions of the user who invoked the command. ### Impact Assessment A successful attack obtains arbitrary command execution under the invokin ...[truncated 316 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/backends/lib/rss.py:18
Finding

Unrestricted URL and RSS Fetching Enables Server-Side Request Forgery

Content
View full analysis
list[tuple[str, str]]: """Parse a podcast RSS feed and return audio enclosure URLs. Returns list of (url, title) tuples, newest-first. """ import urllib.request import xml.etree.ElementTree as ET if not quiet: print(f"📡 Fetching RSS feed: {rss_url}", file=sys.stderr) try: req = urllib.request.Request(rss_url, headers={"User-Agent": "super-transcribe/1.0"}) with urllib.request.urlopen(req, timeout=30) as resp: xml_data = resp.read() except (urllib.error.URLError, OSError, ValueError) as e: print(f"Error fetching RSS feed: {e}", file=sys.stderr) sys.exit(EXIT_BAD_INPUT) ``` From `scripts/backends/lib/audio.py`: ```python def is_url(path: str) -> bool: """Check if the input looks like a URL.""" return path.startswith(("http://", "https://", "www.")) def download_url(url: str, audio_format: str = "wav", quiet: bool = False) -> tuple[str, str]: """Download audio from URL using yt-dlp. Returns (audio_path, tmpdir).""" import sys from .exitcodes import EXIT_BAD_INPUT, EXIT_MISSING_DEP ytdlp = shutil.which("yt-dlp") if not ytdlp: pipx_path = Path.home() / ".local/share/pipx/venvs/yt-dlp/bin/yt-dlp" if pipx_path.exists(): ytdlp = str(pipx_path) else: print("Error: yt-dlp not found. Install with: pipx install yt-dlp", file=sys.stderr) sys.exit(EXIT_MISSING_DEP) tmpdir = tempfile ...[truncated 2589 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/backends/lib/formatters.py:481
Finding

Unescaped Metadata Permits Stored HTML Injection in Transcript Output

Content
View full analysis
str: """Format transcript as HTML with confidence-colored words.""" file_name = result.get("file", "") language = result.get("language", "") duration = result.get("duration", 0) segments = result.get("segments", []) def fmt_ts(s): h = int(s // 3600) m = int((s % 3600) // 60) sec = s % 60 return f"{h:02d}:{m:02d}:{sec:06.3f}" if h else f"{m:02d}:{sec:06.3f}" segs_html = [] for seg in segments: ts = f'[{fmt_ts(seg["start"])} → {fmt_ts(seg["end"])}]' speaker_html = "" if seg.get("speaker"): speaker_html = f' [{seg["speaker"]}]' words = seg.get("words") if words: word_parts = [] for w in words: p = w.get("probability", 1.0) if p >= 0.9: cls = "conf-high" elif p >= 0.7: cls = "conf-med" else: cls = "conf-low" # AIDEV-NOTE: html.escape required — word text may contain angle brackets (XSS) word_parts.append( f'{_html.escape(w["word"])}' ) text_html = "".join(word_parts) else: text_html = _html.escape(seg.get("text", "").strip()) segs_html.append( f'
{ts}{speaker_html} {text_html}
' ) dur_str = f"{int(duration // 60)}m{int(duration % 60)}s" if duration else "" return f"""
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/backends/lib/audio.py:23
Finding

Mutable Unpinned Dependencies and Automatic Runtime Package Installation

Content
View full analysis
=1.2.1 ``` From `scripts/backends/parakeet/requirements.txt`: ```text # Core dependencies — PyTorch installed separately by setup.sh (with CUDA if GPU detected) # IMPORTANT: Use [asr-only] NOT [asr] — [asr] adds ~19 training-only packages # (wandb, transformers, datasets, lightning, pandas, peft, etc.) that are NOT needed for inference. nemo_toolkit[asr-only] # omegaconf is NOT included in [asr-only] but is needed for NeMo diarization config omegaconf<=2.3 ``` From `scripts/backends/lib/audio.py`: ```python def auto_install_package( package_name: str, import_name: str | None = None, quiet: bool = False ) -> bool: """Auto-install a Python package into the current interpreter's environment. Uses uv (preferred) or pip as fallback. Works in venvs and system Python. Returns True if the package is now importable, False otherwise. """ if import_name is None: import_name = package_name try: __import__(import_name.split(".")[0]) return True except ImportError: pass if not quiet: print( f"📦 {package_name} not found — installing automatically (one-time setup)...", file=sys.stderr, ) python_exe = sys.executable try: if shutil.which("uv"): cmd = ["uv", "pip", "install", "--python", python_exe, package_name] else: ...[truncated 2619 chars]
Remediation
View remediation
=`, unconstrained packages, and upper-bound-only constraints with exact versions validated by the project. 4. Remove automatic package installation from transcription execution paths. 5. If a dependency is missing, stop with a clear error and require the user to run an explicit setup command after reviewing the planned changes. 6. Display the exact package versions, indexes, and expected download sources before installation. 7. Restrict package indexes to approved HTTPS repositories and disable unintended extra indexes. 8. Perform dependency updates only through reviewed Skill releases and run vulnerability and integrity scanning as part of that process. 9. Execute ML backends in a sandbox or container with limited filesystem and network access to reduce the impact of a compromised dependency. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (58)

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs the agent to silently transcribe voice messages to infer user intent without explicit opt-in. That creates a privacy and consent problem because the user may be sending spoken content for conversational use, not expecting the system to generate or retain a transcript of the raw audio.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The explicit update feature upgrades installed Python packages from inside the skill, creating a direct software-management capability unrelated to ordinary speech-to-text operation. In agent environments, such capabilities are especially risky because they can be triggered to fetch and execute new code, undermining change control and increasing supply-chain exposure.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill documents capabilities that invoke shell commands, read/write files, inspect environment state, and access the network, but it declares no explicit tool scope or permissions boundary. In an agent setting, that increases the chance of over-broad execution or misuse because the runtime cannot enforce least privilege from the skill manifest alone.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

md
- **Second backend** — auto-installs only when the user triggers a feature that needs it (`--translate` or non-EU language → faster-whisper; `--fast`/`--multitalker` → Parakeet)
- **System deps** — install separately **only if the user needs them**:
  - `ffmpeg` — only for non-WAV input (mp3/m4a/mp4/ogg). Install: `sudo apt install ffmpeg`
  - `yt-dlp` — only for YouTube/URL downloads. Install: `pipx install yt-dlp`
  - HuggingFace token — only for `--diarize` with faster-whisper. Setup: `huggingface-cli login`
- **PyTorch for faster-whisper** — deferred until `--diarize` is first used (saves ~2.8 GB on initial install)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 502)May include surrounding context.

md
- **Second backend** — auto-installs only when the user triggers a feature that needs it (`--translate` or non-EU language → faster-whisper; `--fast`/`--multitalker` → Parakeet)
- **System deps** — install separately **only if the user needs them**:
  - `ffmpeg` — only for non-WAV input (mp3/m4a/mp4/ogg). Install: `sudo apt install ffmpeg`
  - `yt-dlp` — only for YouTube/URL downloads. Install: `pipx install yt-dlp`
  - HuggingFace token — only for `--diarize` with faster-whisper. Setup: `huggingface-cli login`
- **PyTorch for faster-whisper** — deferred until `--diarize` is first used (saves ~2.8 GB on initial install)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/backends/faster-whisper/setup.sh (reported line 193)May include surrounding context.

sh
- **Second backend** — auto-installs only when the user triggers a feature that needs it (`--translate` or non-EU language → faster-whisper; `--fast`/`--multitalker` → Parakeet)
- **System deps** — install separately **only if the user needs them**:
  - `ffmpeg` — only for non-WAV input (mp3/m4a/mp4/ogg). Install: `sudo apt install ffmpeg`
  - `yt-dlp` — only for YouTube/URL downloads. Install: `pipx install yt-dlp`
  - HuggingFace token — only for `--diarize` with faster-whisper. Setup: `huggingface-cli login`
- **PyTorch for faster-whisper** — deferred until `--diarize` is first used (saves ~2.8 GB on initial install)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/backends/parakeet/setup.sh (reported line 221)May include surrounding context.

sh
- **Second backend** — auto-installs only when the user triggers a feature that needs it (`--translate` or non-EU language → faster-whisper; `--fast`/`--multitalker` → Parakeet)
- **System deps** — install separately **only if the user needs them**:
  - `ffmpeg` — only for non-WAV input (mp3/m4a/mp4/ogg). Install: `sudo apt install ffmpeg`
  - `yt-dlp` — only for YouTube/URL downloads. Install: `pipx install yt-dlp`
  - HuggingFace token — only for `--diarize` with faster-whisper. Setup: `huggingface-cli login`
- **PyTorch for faster-whisper** — deferred until `--diarize` is first used (saves ~2.8 GB on initial install)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/backends/parakeet/setup.sh (reported line 222)May include surrounding context.

sh
- **Second backend** — auto-installs only when the user triggers a feature that needs it (`--translate` or non-EU language → faster-whisper; `--fast`/`--multitalker` → Parakeet)
- **System deps** — install separately **only if the user needs them**:
  - `ffmpeg` — only for non-WAV input (mp3/m4a/mp4/ogg). Install: `sudo apt install ffmpeg`
  - `yt-dlp` — only for YouTube/URL downloads. Install: `pipx install yt-dlp`
  - HuggingFace token — only for `--diarize` with faster-whisper. Setup: `huggingface-cli login`
- **PyTorch for faster-whisper** — deferred until `--diarize` is first used (saves ~2.8 GB on initial install)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/backends/parakeet/setup.sh (reported line 223)May include surrounding context.

sh
- **Second backend** — auto-installs only when the user triggers a feature that needs it (`--translate` or non-EU language → faster-whisper; `--fast`/`--multitalker` → Parakeet)
- **System deps** — install separately **only if the user needs them**:
  - `ffmpeg` — only for non-WAV input (mp3/m4a/mp4/ogg). Install: `sudo apt install ffmpeg`
  - `yt-dlp` — only for YouTube/URL downloads. Install: `pipx install yt-dlp`
  - HuggingFace token — only for `--diarize` with faster-whisper. Setup: `huggingface-cli login`
- **PyTorch for faster-whisper** — deferred until `--diarize` is first used (saves ~2.8 GB on initial install)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · setup.sh (reported line 163)May include surrounding context.

sh
- **Second backend** — auto-installs only when the user triggers a feature that needs it (`--translate` or non-EU language → faster-whisper; `--fast`/`--multitalker` → Parakeet)
- **System deps** — install separately **only if the user needs them**:
  - `ffmpeg` — only for non-WAV input (mp3/m4a/mp4/ogg). Install: `sudo apt install ffmpeg`
  - `yt-dlp` — only for YouTube/URL downloads. Install: `pipx install yt-dlp`
  - HuggingFace token — only for `--diarize` with faster-whisper. Setup: `huggingface-cli login`
- **PyTorch for faster-whisper** — deferred until `--diarize` is first used (saves ~2.8 GB on initial install)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · setup.sh (reported line 164)May include surrounding context.

sh
- **Second backend** — auto-installs only when the user triggers a feature that needs it (`--translate` or non-EU language → faster-whisper; `--fast`/`--multitalker` → Parakeet)
- **System deps** — install separately **only if the user needs them**:
  - `ffmpeg` — only for non-WAV input (mp3/m4a/mp4/ogg). Install: `sudo apt install ffmpeg`
  - `yt-dlp` — only for YouTube/URL downloads. Install: `pipx install yt-dlp`
  - HuggingFace token — only for `--diarize` with faster-whisper. Setup: `huggingface-cli login`
- **PyTorch for faster-whisper** — deferred until `--diarize` is first used (saves ~2.8 GB on initial install)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · setup.sh (reported line 221)May include surrounding context.

sh
- **Second backend** — auto-installs only when the user triggers a feature that needs it (`--translate` or non-EU language → faster-whisper; `--fast`/`--multitalker` → Parakeet)
- **System deps** — install separately **only if the user needs them**:
  - `ffmpeg` — only for non-WAV input (mp3/m4a/mp4/ogg). Install: `sudo apt install ffmpeg`
  - `yt-dlp` — only for YouTube/URL downloads. Install: `pipx install yt-dlp`
  - HuggingFace token — only for `--diarize` with faster-whisper. Setup: `huggingface-cli login`
- **PyTorch for faster-whisper** — deferred until `--diarize` is first used (saves ~2.8 GB on initial install)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · setup.sh (reported line 222)May include surrounding context.

sh
- **Second backend** — auto-installs only when the user triggers a feature that needs it (`--translate` or non-EU language → faster-whisper; `--fast`/`--multitalker` → Parakeet)
- **System deps** — install separately **only if the user needs them**:
  - `ffmpeg` — only for non-WAV input (mp3/m4a/mp4/ogg). Install: `sudo apt install ffmpeg`
  - `yt-dlp` — only for YouTube/URL downloads. Install: `pipx install yt-dlp`
  - HuggingFace token — only for `--diarize` with faster-whisper. Setup: `huggingface-cli login`
- **PyTorch for faster-whisper** — deferred until `--diarize` is first used (saves ~2.8 GB on initial install)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · setup.sh (reported line 223)May include surrounding context.

sh
- **Second backend** — auto-installs only when the user triggers a feature that needs it (`--translate` or non-EU language → faster-whisper; `--fast`/`--multitalker` → Parakeet)
- **System deps** — install separately **only if the user needs them**:
  - `ffmpeg` — only for non-WAV input (mp3/m4a/mp4/ogg). Install: `sudo apt install ffmpeg`
  - `yt-dlp` — only for YouTube/URL downloads. Install: `pipx install yt-dlp`
  - HuggingFace token — only for `--diarize` with faster-whisper. Setup: `huggingface-cli login`
- **PyTorch for faster-whisper** — deferred until `--diarize` is first used (saves ~2.8 GB on initial install)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The guidance covers when to transcribe audio but omits a privacy warning for third-party, forwarded, or meeting audio that may contain personal or confidential information. In a transcription skill, that omission increases the risk of processing content without appropriate consent or notice, especially for recordings involving non-users.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 215)May include surrounding context.

md
### Routes to Faster-Whisper Automatically

| Task                      | Command                                                                                           | Why                                                                      |
| ------------------------- | ------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------ |
| **Translate → English**   | `./scripts/transcribe audio.mp3 --translate`                                                      | Whisper-specific feature                                                 |
| **Canary translation**    | `./scripts/transcribe audio.mp3 --backend parakeet --translate --source-lang fr --target-lang de` | NeMo Canary (EN/FR/DE/ES bidirectional)                                  |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 230)May include surrounding context.

md
### Routes to Faster-Whisper Automatically

| Task                      | Command                                                                                           | Why                                                                      |
| ------------------------- | ------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------ |
| **Translate → English**   | `./scripts/transcribe audio.mp3 --translate`                                                      | Whisper-specific feature                                                 |
| **Canary translation**    | `./scripts/transcribe audio.mp3 --backend parakeet --translate --source-lang fr --target-lang de` | NeMo Canary (EN/FR/DE/ES bidirectional)                                  |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 981)May include surrounding context.

md
### Routes to Faster-Whisper Automatically

| Task                      | Command                                                                                           | Why                                                                      |
| ------------------------- | ------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------ |
| **Translate → English**   | `./scripts/transcribe audio.mp3 --translate`                                                      | Whisper-specific feature                                                 |
| **Canary translation**    | `./scripts/transcribe audio.mp3 --backend parakeet --translate --source-lang fr --target-lang de` | NeMo Canary (EN/FR/DE/ES bidirectional)                                  |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 300)May include surrounding context.

md
**⚠️ Do NOT auto-transcribe every voice message.** Determine intent first:

#### When to Transcribe Immediately (No Confirmation Needed)

- User **explicitly asks** for transcription: "transcribe this", "what does this say", "make subtitles for this"
- User sends an **audio/video file** (not a voice note) with a transcription request

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 500)May include surrounding context.

md
### Optional Extras (Not Needed for Basic Transcription)

| Feature                              | Install                                                                                  | Auto-installs?                                                             |
| ------------------------------------ | ---------------------------------------------------------------------------------------- | -------------------------------------------------------------------------- |
| Non-WAV audio (mp3/m4a/mp4)          | `sudo apt install ffmpeg` (Linux) · `brew install ffmpeg` (macOS)                        | No — quickstart reports if missing                                         |
| YouTube/URL downloads                | `pipx install yt-dlp`                                                                    | No                                                                         |

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

The skill supports writing stats sidecar files and many other outputs to disk, but the guidance does not define data retention, path restrictions, or handling of potentially sensitive transcript metadata. In a transcription context, sidecar files can persist filenames, durations, language info, and processing details that may expose user activity or confidential media processing history.

Content

Scanner excerpt · SKILL.md (reported line 610)May include surrounding context.

--burn-in OUTPUT Burn subtitles into video file --rss URL Podcast RSS feed to transcribe --rss-latest N Latest N episodes from RSS (default: 5) --stats-file PATH Write performance stats JSON sidecar

text

### Faster-Whisper Only Options

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1071)May include surrounding context.

md
## Parakeet Troubleshooting

| Problem                              | Solution                                                                                          |
| ------------------------------------ | ------------------------------------------------------------------------------------------------- |
| **CUDA not available**               | Install PyTorch with CUDA: `pip install torch --index-url https://download.pytorch.org/whl/cu121` |
| **NeMo 2.6+ crashes**                | Requires torch >= 2.6.0. Run `./scripts/backends/parakeet/setup.sh --update` to upgrade both torch and NeMo |

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill includes automatic package installation for pyannote.audio on first use, giving it the ability to alter its own environment and download code at runtime. That is broader than necessary for transcription and increases supply-chain and unexpected-network-execution risk in an agent setting.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/backends/faster-whisper/transcribe.py (reported line 185)May include surrounding context.

python
if not audio_path.lower().endswith(".wav"):
        tmp_wav = audio_path + ".diarize.wav"
        try:
            subprocess.run(
                ["ffmpeg", "-y", "-i", audio_path, "-ar", "16000", "-ac", "1", tmp_wav],
                check=True,
                capture_output=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/backends/parakeet/transcribe.py (reported line 520)May include surrounding context.

python
if not audio_path.lower().endswith(".wav"):
        tmp_wav = audio_path + ".diarize.wav"
        try:
            subprocess.run(
                ["ffmpeg", "-y", "-i", audio_path, "-ar", "16000", "-ac", "1", tmp_wav],
                check=True,
                capture_output=True,

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/backends/parakeet/transcribe.py:321