Back to skill

Security audit

Local Voice (FluidAudio TTS/STT)

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local voice skill, but its default setup installs an always-running login service and lacks enough scoping and removal guidance for that persistent behavior.

Install only if you are comfortable with a local voice daemon starting at login and staying alive in your user session. Before installing, review the LaunchAgent behavior, decide whether you want persistence, pin or review Swift dependencies, and make sure you have unload and removal steps for the plist and installed binary.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T06 · System Persistence

Warning
Location
scripts/setup.sh:50
Finding

Unconditional Installation of an Always-On LaunchAgent

Content
View full analysis
"$PLIST_DIR/com.stella.voice.plist" << EOF Label com.stella.voice ProgramArguments ${INSTALL_DIR}/StellaVoice EnvironmentVariables HOME ${HOME} RunAtLoad KeepAlive StandardOutPath ${LOG_DIR}/stella-voice.log StandardErrorPath ${LOG_DIR}/stella-voice.err.log WorkingDirectory ${HOME} EOF # Load service echo "🔄 Loading service..." launchctl unload "$PLIST_DIR/com.stella.voice.plist" 2>/dev/null || true launchctl load "$PLIST_DIR/com.stella.voice.plist" ``` ### Technical Analysis The setup script unconditionally creates and loads a per-user macOS LaunchAgent. The combination of `RunAtLoad` and `KeepAlive` causes the service to start when the user session loads and to be restarted after termination. A continuously running local daemon can be useful for low-latency voice functionality, and the persistence behavior is disclosed in the documentation. However, persistence is not strictly necessary to provide local TTS/STT functionality. An on-demand process or explicitly enabled optional service would satisfy the declared functionality with less persistent execution and resource exposure. The LaunchAgent executes a binary from the stable user-writable path `~/clawd/bin/StellaVoice`. If ...[truncated 1495 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
sources/Package.swift:5
Finding

Dependency Versions Are Not Reproducibly Pinned

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (37)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description advertises both TTS and STT capabilities, but this code only performs TTS requests to an already-running local service. There is no transcription, audio input handling, or STT logic. The code’s primary purpose is still related to local voice synthesis, so it partially matches, but the declared description materially overstates the implemented capabilities in this chunk.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/setup.sh (reported line 44)May include surrounding context.

sh
# Install framework
if [[ -d ".build/arm64-apple-macosx/release/ESpeakNG.framework" ]]; then
    rm -rf "$INSTALL_DIR/ESpeakNG.framework"
    cp -R .build/arm64-apple-macosx/release/ESpeakNG.framework "$INSTALL_DIR/"
fi

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill includes shell installation and setup commands, including package installation, binary copying, and LaunchAgent creation, but does not declare any tool scope or permissions. This creates an unsafe trust boundary because an agent may execute system-modifying shell actions without explicit user visibility or policy constraints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The installation instructions create and load a macOS LaunchAgent that runs at login and keeps itself alive, which is a persistent system behavior change. Doing this without an explicit warning can mislead users into establishing background execution they did not fully understand, increasing operational and security risk.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

The plist creation is part of establishing login persistence for the voice daemon. Persistence mechanisms are security-relevant because they cause software to restart automatically and can make later compromise or misuse harder for users to notice and remove.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

4. Create LaunchAgent

bash
cat > ~/Library/LaunchAgents/com.stella.tts.plist << 'EOF'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The PLIST content defines a background service configuration, which is a classic persistence mechanism. In a benign local voice skill this may be functional, but it still changes runtime behavior beyond the current session and should be explicitly disclosed.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

bash
cat > ~/Library/LaunchAgents/com.stella.tts.plist << 'EOF'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>Label</key>

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The PLIST content defines a background service configuration, which is a classic persistence mechanism. In a benign local voice skill this may be functional, but it still changes runtime behavior beyond the current session and should be explicitly disclosed.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

bash
cat > ~/Library/LaunchAgents/com.stella.tts.plist << 'EOF'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>Label</key>

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The LaunchAgent label is part of registering a named login item that will persist across sessions. Such mechanisms are commonly abused in malware, so even benign uses require transparency and careful scoping.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
cat > ~/Library/LaunchAgents/com.stella.tts.plist << 'EOF'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>Label</key>
    <string>com.stella.tts</string>

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

The closing portion of the plist is still part of the same persistence setup and therefore materially contributes to session persistence. The risk is contextual rather than overtly malicious: a background daemon is being installed without strong safety framing.

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
<key>StandardErrorPath</key>
    <string>$HOME/.clawdbot/logs/stella-tts.err.log</string>
</dict>
</plist>
EOF

launchctl load ~/Library/LaunchAgents/com.stella.tts.plist

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

This is another reference to the same persisted LaunchAgent path and is part of enabling background execution. Repetition does not add new maliciousness, but it confirms the setup is intended to survive across sessions.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

EOF

launchctl load ~/Library/LaunchAgents/com.stella.tts.plist

text

## API Endpoints

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

This is another reference to the same persisted LaunchAgent path and is part of enabling background execution. Repetition does not add new maliciousness, but it confirms the setup is intended to survive across sessions.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

EOF

launchctl load ~/Library/LaunchAgents/com.stella.tts.plist

text

## API Endpoints

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

bash
# Simple text to WAV
curl -X POST http://127.0.0.1:18790/synthesize -d "Hello world" -o output.wav

# With speed control (0.5-2.0)
curl -X POST "http://127.0.0.1:18790/synthesize?speed=1.2" -d "Fast!" -o output.wav

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

javascript
// STT
const response = await fetch('http://127.0.0.1:18790/transcribe', {
    method: 'POST',
    headers: { 'Content-Type': 'audio/wav' },
    body: audioData

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

javascript
// STT
const response = await fetch('http://127.0.0.1:18790/transcribe', {
    method: 'POST',
    headers: { 'Content-Type': 'audio/wav' },
    body: audioData

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · SKILL.md (reported line 165)May include surrounding context.

javascript
// STT
const response = await fetch('http://127.0.0.1:18790/transcribe', {
    method: 'POST',
    headers: { 'Content-Type': 'audio/wav' },
    body: audioData

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 165)May include surrounding context.

md
const { text } = await response.json();

// TTS
const audio = await fetch('http://127.0.0.1:18790/synthesize', {
    method: 'POST',
    body: textToSpeak
});

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/setup.sh (reported line 10)May include surrounding context.

sh
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
SKILL_DIR="$(dirname "$SCRIPT_DIR")"
INSTALL_DIR="${HOME}/clawd/bin"
PLIST_DIR="${HOME}/Library/LaunchAgents"
LOG_DIR="${HOME}/.clawdbot/logs"

echo "🚀 StellaVoice Setup"

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/setup.sh (reported line 53)May include surrounding context.

sh
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
SKILL_DIR="$(dirname "$SCRIPT_DIR")"
INSTALL_DIR="${HOME}/clawd/bin"
PLIST_DIR="${HOME}/Library/LaunchAgents"
LOG_DIR="${HOME}/.clawdbot/logs"

echo "🚀 StellaVoice Setup"

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/setup.sh (reported line 55)May include surrounding context.

sh
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
SKILL_DIR="$(dirname "$SCRIPT_DIR")"
INSTALL_DIR="${HOME}/clawd/bin"
PLIST_DIR="${HOME}/Library/LaunchAgents"
LOG_DIR="${HOME}/.clawdbot/logs"

echo "🚀 StellaVoice Setup"

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/setup.sh (reported line 85)May include surrounding context.

sh
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
SKILL_DIR="$(dirname "$SCRIPT_DIR")"
INSTALL_DIR="${HOME}/clawd/bin"
PLIST_DIR="${HOME}/Library/LaunchAgents"
LOG_DIR="${HOME}/.clawdbot/logs"

echo "🚀 StellaVoice Setup"

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/setup.sh (reported line 86)May include surrounding context.

sh
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
SKILL_DIR="$(dirname "$SCRIPT_DIR")"
INSTALL_DIR="${HOME}/clawd/bin"
PLIST_DIR="${HOME}/Library/LaunchAgents"
LOG_DIR="${HOME}/.clawdbot/logs"

echo "🚀 StellaVoice Setup"

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/setup.sh (reported line 103)May include surrounding context.

sh
echo "  GET  http://127.0.0.1:18790/health      - Health"
    echo ""
    echo "Test TTS:"
    echo "  curl -X POST http://127.0.0.1:18790/synthesize -d 'Hello!' -o test.wav"
else
    echo "❌ Service failed to start. Check logs:"
    echo "  tail -f $LOG_DIR/stella-voice.err.log"

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/stella-tts.sh (reported line 19)May include surrounding context.

sh
fi

# Check if daemon is running
if ! curl -s http://127.0.0.1:18790/health > /dev/null 2>&1; then
    echo "Error: StellaTTS daemon not running" >&2
    echo "Start it with: launchctl load ~/Library/LaunchAgents/com.stella.tts.plist" >&2
    exit 1

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/setup.sh (reported line 53)May include surrounding context.

sh
# Check if daemon is running
if ! curl -s http://127.0.0.1:18790/health > /dev/null 2>&1; then
    echo "Error: StellaTTS daemon not running" >&2
    echo "Start it with: launchctl load ~/Library/LaunchAgents/com.stella.tts.plist" >&2
    exit 1
fi

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/setup.sh (reported line 55)May include surrounding context.

sh
# Check if daemon is running
if ! curl -s http://127.0.0.1:18790/health > /dev/null 2>&1; then
    echo "Error: StellaTTS daemon not running" >&2
    echo "Start it with: launchctl load ~/Library/LaunchAgents/com.stella.tts.plist" >&2
    exit 1
fi

Static analysis

No suspicious patterns detected.