Back to skill

Security audit

China Tts

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent cloud text-to-speech helper, but its voice-cloning workflow uploads sensitive voice samples without clear consent, privacy, or retention safeguards.

Review before installing. Use this only if you are comfortable sending TTS text and any reference voice recordings to SiliconFlow. Do not submit secrets, regulated data, or voices you do not own or have explicit permission to clone. Treat the API key and cloned voice URI as sensitive, and clean up generated audio or provider-side custom voices when no longer needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (24)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

  1. 进入「API密钥」页面,创建并复制 API Key
  2. 在 OpenClaw 中配置: export SILICONFLOW_API_KEY="sk-xxxxxxxxxxxxxxxx" 或写入 ~/.openclaw/.env

注意:使用自定义音色(声音克隆)需要完成实名认证

text

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The voice-cloning workflow tells users to upload a reference voice sample and reuse the returned voice identifier, but omits any warning about consent, biometric sensitivity, impersonation risk, or downstream retention by the remote provider. Voice data is especially sensitive because it can enable spoofing, identity abuse, and unauthorized cloning of another person's speech.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill sends user-provided text to SiliconFlow for synthesis and, for voice cloning, instructs uploading reference voice audio to the provider, but it does not prominently warn users that this content leaves the local environment. This creates a real privacy risk because sensitive text, biometric voice data, and associated metadata may be transmitted to and processed by a third party without informed consent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
85% confidence
Finding

The direct reference to the SiliconFlow API endpoint confirms use of an external service. In this skill context the endpoint itself is not malicious, but its use means user content and bearer-authenticated requests leave the local trust boundary.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

基础朗读(CosyVoice2,系统预置音色)

bash
curl --location 'https://api.siliconflow.cn/v1/audio/speech' \
  --header "Authorization: Bearer $SILICONFLOW_API_KEY" \
  --header 'Content-Type: application/json' \
  --data '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
85% confidence
Finding

The direct reference to the SiliconFlow API endpoint confirms use of an external service. In this skill context the endpoint itself is not malicious, but its use means user content and bearer-authenticated requests leave the local trust boundary.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

基础朗读(CosyVoice2,系统预置音色)

bash
curl --location 'https://api.siliconflow.cn/v1/audio/speech' \
  --header "Authorization: Bearer $SILICONFLOW_API_KEY" \
  --header 'Content-Type: application/json' \
  --data '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
85% confidence
Finding

This endpoint reference supports external processing of dialogue synthesis. The risk is contextual rather than inherently malicious: the skill is designed for cloud TTS, but users are not adequately warned that their text is sent off-device.

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

双人对话(MOSS-TTSD,播客场景)

bash
curl --location 'https://api.siliconflow.cn/v1/audio/speech' \
  --header "Authorization: Bearer $SILICONFLOW_API_KEY" \
  --header 'Content-Type: application/json' \
  --data '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
85% confidence
Finding

This endpoint reference supports external processing of dialogue synthesis. The risk is contextual rather than inherently malicious: the skill is designed for cloud TTS, but users are not adequately warned that their text is sent off-device.

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

双人对话(MOSS-TTSD,播客场景)

bash
curl --location 'https://api.siliconflow.cn/v1/audio/speech' \
  --header "Authorization: Bearer $SILICONFLOW_API_KEY" \
  --header 'Content-Type: application/json' \
  --data '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

Uploading reference audio for voice cloning sends biometric voice data to an external provider, which is substantially more sensitive than ordinary text submission. Combined with the note about real-name verification, this raises elevated privacy and misuse concerns because voiceprints may enable impersonation, identity linkage, or long-term biometric exposure.

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

bash
# 先上传参考音频(一次性操作,30秒以内的清晰录音)
curl --location 'https://api.siliconflow.cn/v1/uploads/audio/voice' \
  --header "Authorization: Bearer $SILICONFLOW_API_KEY" \
  --form 'model="FunAudioLLM/CosyVoice2-0.5B"' \
  --form 'customName="my-voice"' \

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This cloned-voice synthesis request uses a previously uploaded custom voice identifier with the external service, meaning personalized voice assets and input text are processed remotely. The presence of custom cloned voices increases the chance of misuse for impersonation or unauthorized reproduction of a person's voice.

Content

Scanner excerpt · SKILL.md (reported line 165)May include surrounding context.

md
# 返回 uri 字段,格式:speech:my-voice:xxxxx:xxxxx
# 将 uri 作为 voice 参数使用
curl --location 'https://api.siliconflow.cn/v1/audio/speech' \
  --header "Authorization: Bearer $SILICONFLOW_API_KEY" \
  --header 'Content-Type: application/json' \
  --data '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

This output-path example still includes an external network request to the TTS API, so the same data-transfer risk applies. The surrounding context also normalizes automatic file creation, compounding privacy exposure by both transmitting content externally and storing the resulting audio locally.

Content

Scanner excerpt · SKILL.md (reported line 256)May include surrounding context.

md
FILENAME="tts_$(date +%Y%m%d_%H%M%S).mp3"
OUTPUT_PATH="$OUTPUT_DIR/$FILENAME"

# 完整 curl 命令示例
curl --location 'https://api.siliconflow.cn/v1/audio/speech' \
  --header "Authorization: Bearer $SILICONFLOW_API_KEY" \
  --header 'Content-Type: application/json' \

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

This endpoint reference in the save-path example again indicates off-device processing by SiliconFlow. While expected for a cloud TTS skill, it remains a true finding because the skill lacks a strong privacy warning and may be used on sensitive material in agent workflows.

Content

Scanner excerpt · SKILL.md (reported line 257)May include surrounding context.

md
OUTPUT_PATH="$OUTPUT_DIR/$FILENAME"

# 完整 curl 命令示例
curl --location 'https://api.siliconflow.cn/v1/audio/speech' \
  --header "Authorization: Bearer $SILICONFLOW_API_KEY" \
  --header 'Content-Type: application/json' \
  --data '{...}' \

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This example performs an external API call that transmits user-provided text and an API credential to a remote service. The transmission itself is expected for cloud TTS, but without contextual warnings or safeguards it creates a real data-exposure risk if users submit sensitive content.

Content

Scanner excerpt · references/examples.md (reported line 7)May include surrounding context.

bash
OUTPUT_DIR="${OPENCLAW_WORKSPACE:-$PWD}/tts" && mkdir -p "$OUTPUT_DIR"
curl --location 'https://api.siliconflow.cn/v1/audio/speech' \
  --header "Authorization: Bearer $SILICONFLOW_API_KEY" \
  --header 'Content-Type: application/json' \
  --data '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This example performs an external API call that transmits user-provided text and an API credential to a remote service. The transmission itself is expected for cloud TTS, but without contextual warnings or safeguards it creates a real data-exposure risk if users submit sensitive content.

Content

Scanner excerpt · references/examples.md (reported line 7)May include surrounding context.

bash
OUTPUT_DIR="${OPENCLAW_WORKSPACE:-$PWD}/tts" && mkdir -p "$OUTPUT_DIR"
curl --location 'https://api.siliconflow.cn/v1/audio/speech' \
  --header "Authorization: Bearer $SILICONFLOW_API_KEY" \
  --header 'Content-Type: application/json' \
  --data '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The examples instruct users to send arbitrary article/blog text to a third-party TTS API but provide no notice that the content leaves the local environment and may contain sensitive or copyrighted material. In a skill explicitly marketed for domestic use without VPN, users may be encouraged to paste large bodies of text, increasing the chance of unintentional disclosure.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This podcast-style example sends dialogue content to a third-party endpoint for synthesis. Because the skill is designed to process user-authored content, the main risk is unannounced exfiltration of potentially confidential text rather than code execution or direct compromise.

Content

Scanner excerpt · references/examples.md (reported line 61)May include surrounding context.

bash
OUTPUT_DIR="${OPENCLAW_WORKSPACE:-$PWD}/tts" && mkdir -p "$OUTPUT_DIR"
curl --location 'https://api.siliconflow.cn/v1/audio/speech' \
  --header "Authorization: Bearer $SILICONFLOW_API_KEY" \
  --header 'Content-Type: application/json' \
  --data '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This podcast-style example sends dialogue content to a third-party endpoint for synthesis. Because the skill is designed to process user-authored content, the main risk is unannounced exfiltration of potentially confidential text rather than code execution or direct compromise.

Content

Scanner excerpt · references/examples.md (reported line 61)May include surrounding context.

bash
OUTPUT_DIR="${OPENCLAW_WORKSPACE:-$PWD}/tts" && mkdir -p "$OUTPUT_DIR"
curl --location 'https://api.siliconflow.cn/v1/audio/speech' \
  --header "Authorization: Bearer $SILICONFLOW_API_KEY" \
  --header 'Content-Type: application/json' \
  --data '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

This example uploads a reference audio file to a remote voice-cloning endpoint, which is a meaningful external transfer of sensitive biometric-like voice data. In the context of voice cloning, the lack of consent and privacy warnings makes the data-sharing risk substantially more dangerous than ordinary TTS input.

Content

Scanner excerpt · references/examples.md (reported line 92)May include surrounding context.

第一步:上传参考音频(一次性)

bash
curl --location 'https://api.siliconflow.cn/v1/uploads/audio/voice' \
  --header "Authorization: Bearer $SILICONFLOW_API_KEY" \
  --form 'model="FunAudioLLM/CosyVoice2-0.5B"' \
  --form 'customName="my-voice"' \

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This follow-up example sends text plus a reusable cloned-voice identifier to the remote API, enabling continued use of a previously uploaded custom voice. While normal for the feature, it increases misuse potential if the identifier corresponds to an unauthorized or sensitive voice clone.

Content

Scanner excerpt · references/examples.md (reported line 107)May include surrounding context.

bash
OUTPUT_DIR="${OPENCLAW_WORKSPACE:-$PWD}/tts" && mkdir -p "$OUTPUT_DIR"
curl --location 'https://api.siliconflow.cn/v1/audio/speech' \
  --header "Authorization: Bearer $SILICONFLOW_API_KEY" \
  --header 'Content-Type: application/json' \
  --data '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/voices.md (reported line 75)May include surrounding context.

查看已上传的自定义音色

bash
curl --location 'https://api.siliconflow.cn/v1/audio/voice/list' \
  --header "Authorization: Bearer $SILICONFLOW_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/voices.md (reported line 75)May include surrounding context.

查看已上传的自定义音色

bash
curl --location 'https://api.siliconflow.cn/v1/audio/voice/list' \
  --header "Authorization: Bearer $SILICONFLOW_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/voices.md (reported line 82)May include surrounding context.

查看已上传的自定义音色

bash
curl --location 'https://api.siliconflow.cn/v1/audio/voice/list' \
  --header "Authorization: Bearer $SILICONFLOW_API_KEY"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file includes a concrete example for deleting custom voices via the /v1/audio/voice/deletions endpoint, but it does not warn that the action removes user-created assets and may be irreversible. Under the markdown-specific warning criteria, destructive operations affecting user data should include a clear caution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill documents automatic saving of generated audio into the workspace and retention of historical files, but does not present this as a user-facing warning before use. This can expose sensitive synthesized content to other local users, later agents, backups, or source-control workflows if the workspace is shared or synced.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file’s natural-language content is exclusively Chinese, which effectively forces a specific language for users reading the skill documentation. The policy allows locale constraints only when the skill offers a language choice or clearly documents a justified region-specific limitation, neither of which appears here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.