Back to skill

Security audit

Meeting QA To Audio

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent meeting-summary and audio purpose, but it handles sensitive meeting notes too broadly by storing plaintext meeting data, shipping populated memory files, and allowing raw meeting text to be sent to an external TTS service.

Review this skill carefully before installing. It is not clearly malicious, but use it only with meeting notes you are comfortable storing locally and sending to SenseAudio for speech generation. Remove bundled memory JSON files, avoid sensitive or internal URLs, prefer summary/answer audio over full-text audio, and require explicit consent plus a clear deletion path before retaining meeting contents.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/read_meeting_minutes_aloud.py:6
Finding

Full meeting text can be transmitted to an external TTS service without explicit consent

Content
View full analysis
str: input_text = read_text_source(location) if input_text.startswith("ERROR:"): return input_text return generate_meeting_audio( input_text=input_text, output_path=output_path, mode=mode, voice_id=voice_id, api_key=api_key, ) ``` The data reaches the following external network sink: ```python payload = { "model": API_MODEL, "text": prepared["text"], "stream": False, "voice_setting": { "voice_id": final_voice_id, "speed": 1, "vol": 1, "pitch": 0, }, "audio_setting": { "sample_rate": DEFAULT_SAMPLE_RATE, "bitrate": DEFAULT_BITRATE, "format": DEFAULT_AUDIO_FORMAT, "channel": DEFAULT_CHANNELS, }, } headers = { "Authorization": f"Bearer {resolved_api_key}", "Content-Type": "application/json", } try: response = requests.post( API_URL, headers=headers, json=payload, timeout=REQUEST_TIMEOUT, ) ``` ### Technical Analysis The declared primary workflow uses SenseAudio to synthesize the generated summary and subsequent answers. However, `read_meeting_minutes_aloud()` exposes a separate executable flow whose default mode is `full_text`. It reads the source meeting note and passes it directly to `generate_meeting_audio()`, which places the prepared text in a request to `https://api.senseaudio.cn/v1/t2a_v2`. The preprocessing logic limits transmitted content to 1,000 characters by default, un ...[truncated 1859 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_meeting_audio.py:147
Finding

Unrestricted meeting-source URL retrieval enables server-side request forgery

Content
View full analysis
str: if location.startswith(("http://", "https://")): try: response = requests.get(location, timeout=REQUEST_TIMEOUT) except requests.exceptions.Timeout: return f"ERROR: Request timed out after {REQUEST_TIMEOUT}s" except requests.RequestException as exc: return f"ERROR: Failed to fetch URL: {exc}" if response.status_code != 200: return f"ERROR: URL fetch failed with status code {response.status_code}" return _normalize_source_text(response.text) ``` ### Technical Analysis The `location` value is user-controlled and is fetched whenever it begins with `http://` or `https://`. The implementation does not validate the destination host or resolved IP address. In particular, it does not reject: - Loopback addresses such as `127.0.0.1` or `::1`. - RFC 1918 private networks. - Link-local addresses, including cloud metadata ranges. - Reserved, multicast, or otherwise non-public addresses. - Hostnames that resolve to internal addresses. - Redirects from a public destination to an internal destination. - DNS rebinding or resolution changes between validation and connection. `requests.get()` follows redirects by default. Consequently, validating only the URL prefix is not an effective network-boundary control. There is also no response-size or content-type restriction, creating an additional denial-of-service exposure if a remote endpoint returns a very large body. ### Attack Path 1. An attacker supplies a meeting source such as an internal HTTP URL, a cloud metadata URL, or a public URL that redirects to an internal service. 2. The Skill accepts the value because it starts with `http:// ...[truncated 1120 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/meeting_memory.py:20
Finding

Full meeting minutes and source paths are retained and distributed in plaintext

Content
View full analysis
str: target = Path(memory_path).expanduser().resolve() if memory_path else default_memory_path() target.parent.mkdir(parents=True, exist_ok=True) payload = { "saved_at": datetime.now().isoformat(timespec="seconds"), "source_location": source_location, "meeting_text": meeting_text, "summary_text": summary_text, } target.write_text( json.dumps(payload, ensure_ascii=False, indent=2), encoding="utf-8", ) return str(target) ``` The distributed project contains populated memory records with this structure: ```json { "saved_at": "2026-03-17T11:40:45", "source_location": "D:\\周报\\会议纪要\\20260114周会.txt", "meeting_text": "20260114周会\n...", "summary_text": "..." } ``` ### Technical Analysis The Skill intentionally stores meeting context locally for follow-up questions, but it persists the complete meeting text, source path, timestamp, and summary as unencrypted JSON. The file is created using the process’s default filesystem permissions; the code does not explicitly enforce owner-only access. There is no retention duration, automatic deletion, content minimization, or cleanup function. A caller may also supply an arbitrary `memory_path`, so sensitive meeting data can be written outside the Skill’s default memory directory. This override is documented, but it increases the need for explicit path and permission controls. More importantly, the audited project already includes populated `memory/latest_meeting.json` and `memory/current_meeting ...[truncated 1589 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (31)

Tainted flow: 'payload' from os.getenv (line 64, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/generate_meeting_audio.py (reported line 87)May include surrounding context.

python
}

    try:
        response = requests.post(API_URL, headers=headers, json=payload, timeout=REQUEST_TIMEOUT)
    except requests.exceptions.Timeout:
        return f"ERROR: SenseAudio request timed out after {REQUEST_TIMEOUT}s"
    except requests.RequestException as exc:

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A meeting-minutes skill that may not actually support URL handling, local memory storage, follow-up Q&A, or audio generation for both stages can misroute sensitive data and break expected review controls. The context makes this more dangerous because meeting notes are often confidential and local persistence plus external TTS create real privacy and exfiltration concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

A meeting-minutes skill that may not actually support URL handling, local memory storage, follow-up Q&A, or audio generation for both stages can misroute sensitive data and break expected review controls. The context makes this more dangerous because meeting notes are often confidential and local persistence plus external TTS create real privacy and exfiltration concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

A meeting-minutes skill that may not actually support URL handling, local memory storage, follow-up Q&A, or audio generation for both stages can misroute sensitive data and break expected review controls. The context makes this more dangerous because meeting notes are often confidential and local persistence plus external TTS create real privacy and exfiltration concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A meeting-minutes skill that may not actually support URL handling, local memory storage, follow-up Q&A, or audio generation for both stages can misroute sensitive data and break expected review controls. The context makes this more dangerous because meeting notes are often confidential and local persistence plus external TTS create real privacy and exfiltration concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

A meeting-minutes skill that may not actually support URL handling, local memory storage, follow-up Q&A, or audio generation for both stages can misroute sensitive data and break expected review controls. The context makes this more dangerous because meeting notes are often confidential and local persistence plus external TTS create real privacy and exfiltration concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A meeting-minutes skill that may not actually support URL handling, local memory storage, follow-up Q&A, or audio generation for both stages can misroute sensitive data and break expected review controls. The context makes this more dangerous because meeting notes are often confidential and local persistence plus external TTS create real privacy and exfiltration concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A meeting-minutes skill that may not actually support URL handling, local memory storage, follow-up Q&A, or audio generation for both stages can misroute sensitive data and break expected review controls. The context makes this more dangerous because meeting notes are often confidential and local persistence plus external TTS create real privacy and exfiltration concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A meeting-minutes skill that may not actually support URL handling, local memory storage, follow-up Q&A, or audio generation for both stages can misroute sensitive data and break expected review controls. The context makes this more dangerous because meeting notes are often confidential and local persistence plus external TTS create real privacy and exfiltration concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A meeting-minutes skill that may not actually support URL handling, local memory storage, follow-up Q&A, or audio generation for both stages can misroute sensitive data and break expected review controls. The context makes this more dangerous because meeting notes are often confidential and local persistence plus external TTS create real privacy and exfiltration concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

A meeting-minutes skill that may not actually support URL handling, local memory storage, follow-up Q&A, or audio generation for both stages can misroute sensitive data and break expected review controls. The context makes this more dangerous because meeting notes are often confidential and local persistence plus external TTS create real privacy and exfiltration concerns.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The PRD explicitly stores the latest meeting context in a local JSON file, but it does not require a clear user warning or consent flow for retaining potentially sensitive meeting notes on disk. Meeting minutes often contain confidential business discussions, personnel details, or action items, so silent persistence increases the risk of unintended disclosure to other local users, backups, or malware.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises behaviors that require environment access, file reads/writes, and network access, but it declares no explicit tool scope or permission boundaries. That increases the risk of overbroad execution, confused-deputy behavior, and unsafe handling of sensitive inputs such as local meeting notes and API keys.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description says it saves meeting text and summaries into local memory/files but does not prominently warn about that retention. Because meeting minutes commonly contain confidential or regulated information, undisclosed local persistence can expose sensitive data to later users, backups, sync tools, or other local processes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Forcing a Chinese spoken-style summary without documenting user choice can cause privacy, integrity, and usability issues, especially if the meeting language differs or if the summary will be shared with unintended audiences. It is primarily a transparency and product-safety issue rather than a direct exploit vector, but it can still lead to miscommunication around sensitive meeting content.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The default prompt is broad enough to encourage automatic execution of multiple sensitive actions: reading arbitrary local paths or URLs, storing meeting content in local memory, and writing mp3 files. Without tighter trigger constraints or explicit user-confirmation boundaries, the skill could be invoked in situations where users did not clearly intend persistent storage, remote content retrieval, or file creation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description omits an explicit warning that meeting contents will be retained in local memory and that audio files containing potentially sensitive meeting information will be saved to disk. In a meeting-notes context, this is more dangerous because the data commonly includes confidential business, HR, legal, or product information, so silent retention and file output can create privacy and data-handling risks.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/generate_meeting_audio.py (reported line 11)May include surrounding context.

python
import requests


API_URL = "https://api.senseaudio.cn/v1/t2a_v2"
API_MODEL = "SenseAudio-TTS-1.0"
DEFAULT_VOICE_ID = "male_0004_a"
DEFAULT_AUDIO_FORMAT = "mp3"

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This line performs external transmission of meeting text to a third-party API. While network transmission is core to TTS functionality, it is still a real privacy/security concern here because sensitive meeting contents leave the local environment and no code-level safeguard ensures informed consent or minimization.

Content

Scanner excerpt · scripts/generate_meeting_audio.py (reported line 87)May include surrounding context.

python
}

    try:
        response = requests.post(API_URL, headers=headers, json=payload, timeout=REQUEST_TIMEOUT)
    except requests.exceptions.Timeout:
        return f"ERROR: SenseAudio request timed out after {REQUEST_TIMEOUT}s"
    except requests.RequestException as exc:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Meeting minutes can contain sensitive business, personal, or legal information, and this code transmits the selected text to a third-party TTS service without any built-in consent prompt, warning, or redaction control. In the skill context, this is more dangerous because the feature is specifically designed for meeting notes, which are often confidential.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest says the skill should read meeting minutes, produce a short summary with the current conversation model, and answer later follow-up questions about the same meeting. In this file, the only 'summary' behavior is taking the first six non-empty lines or keyword-matching lines; there is no use of any conversation model, no memory persistence, and no question-answering logic.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The functions accept a caller-supplied memory_path and resolve it directly, allowing reads from and writes to arbitrary filesystem locations instead of restricting access to the skill's intended local memory directory. In a skill that processes sensitive meeting notes, this can expose confidential data, overwrite unrelated files accessible to the agent, or retrieve data from unintended locations if an attacker can influence the path.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code persists full meeting_text and summary_text to disk, which may contain sensitive business discussions, personal data, or secrets, without any built-in consent check, minimization, or warning mechanism. In this skill's context, silent storage increases privacy and compliance risk because users may expect a transient summary/Q&A flow rather than durable local retention of the entire meeting contents.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a skill that reads meeting minutes, produces a short summary, saves the meeting text and summary into local memory, and answers later follow-up questions about that same meeting. In this file, the code only reads a text source and passes it to an audio-generation helper, exposing mode options such as full_text/action_items/decisions/summary, with no code for conversation summarization, memory persistence, or question answering.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The PRD says the skill should ask where the mp3 should be saved, but it does not explicitly warn that generated audio files will be written to disk and may contain sensitive meeting summaries or answers. This can lead users to unintentionally create persistent artifacts of confidential content, especially if saved in shared or synced directories.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.