T09 · Insecure Skill Coding Practices
- Location
scripts/read_meeting_minutes_aloud.py:6- Finding
Full meeting text can be transmitted to an external TTS service without explicit consent
- Content
View full analysis
str: input_text = read_text_source(location) if input_text.startswith("ERROR:"): return input_text return generate_meeting_audio( input_text=input_text, output_path=output_path, mode=mode, voice_id=voice_id, api_key=api_key, ) ``` The data reaches the following external network sink: ```python payload = { "model": API_MODEL, "text": prepared["text"], "stream": False, "voice_setting": { "voice_id": final_voice_id, "speed": 1, "vol": 1, "pitch": 0, }, "audio_setting": { "sample_rate": DEFAULT_SAMPLE_RATE, "bitrate": DEFAULT_BITRATE, "format": DEFAULT_AUDIO_FORMAT, "channel": DEFAULT_CHANNELS, }, } headers = { "Authorization": f"Bearer {resolved_api_key}", "Content-Type": "application/json", } try: response = requests.post( API_URL, headers=headers, json=payload, timeout=REQUEST_TIMEOUT, ) ``` ### Technical Analysis The declared primary workflow uses SenseAudio to synthesize the generated summary and subsequent answers. However, `read_meeting_minutes_aloud()` exposes a separate executable flow whose default mode is `full_text`. It reads the source meeting note and passes it directly to `generate_meeting_audio()`, which places the prepared text in a request to `https://api.senseaudio.cn/v1/t2a_v2`. The preprocessing logic limits transmitted content to 1,000 characters by default, un ...[truncated 1859 chars]- Remediation
View remediation
