Back to skill

Security audit

Deepdub TTS

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says: it sends text to Deepdub, creates an audio file, and exposes no hidden persistence or unrelated access, but users should replace the shared trial credential and pin the dependency.

Install only in an isolated, unprivileged environment, use your own Deepdub API key for real work, avoid relying on the shared trial credential, and pin or lock the deepdub package before production use. Configure OPENCLAW_MEDIA_DIR to a directory intended for generated audio files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:33
Finding

Rate-Limited Deepdub API Credential Embedded in Documentation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 33-40
Vulnerability Type: Hardcoded credential and plaintext sensitive data
Risk Level: Low

Vulnerable Code Snippet:

markdown
### Free Trial Credentials
For testing only, you can use these free trial credentials:
text
DEEPDUB_API_KEY=dd-00000000000000000000000065c9cbfe
DEEPDUB_VOICE_PROMPT_ID=11f3403d-35b9-4817-8d55-f41694ea6227
markdown
> **Note:** These are rate-limited trial credentials for evaluation purposes only. Do not use for production. Obtain your own API key and voice prompts from Deepdub for production use.

Technical Analysis

The project distributes a usable Deepdub trial API key and voice prompt identifier as plaintext documentation. Although the documentation identifies the credential as rate-limited and intended only for evaluation, every recipient of the package can extract and use it independently of the skill.

Publicly distributing a shared credential removes user-level accountability and prevents reliable attribution of API activity. It also permits unrelated parties to consume the shared quota, trigger provider-side abuse controls, or cause the credential to be revoked. If the credential has capabilities beyond speech synthesis or if provider-side permissions change, the impact could increase.

No evidence indicates that this credential grants local system access, production account access, or elevated privileges. The confirmed scope is limited to whatever permissions and quota Deepdub assigns to this trial credential.

Attack Path

  1. An attacker downloads the skill or views SKILL.md.
  2. The attacker copies the plaintext DEEPDUB_API_KEY and DEEPDUB_VOICE_PROMPT_ID.
  3. The attacker submits requests directly to the Deepdub service using those values.
  4. The shared trial quota may be consumed, abusive content may be generated under the shared identity, or provider rate lim ...[truncated 590 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove the API key and voice prompt identifier from all distributed documentation and repository history.
  • Revoke or rotate the disclosed trial credential with Deepdub.
  • Require each user to obtain an individual trial or production credential through the provider's normal enrollment process.
  • Provide placeholders instead of functional values:
    text
    DEEPDUB_API_KEY=your_api_key_here
    DEEPDUB_VOICE_PROMPT_ID=your_voice_prompt_id_here
    
  • Store credentials only in environment variables or an approved secret manager.
  • Add automated secret scanning to CI and pre-commit checks.
  • If shared evaluation access is necessary, place it behind a controlled proxy that enforces per-user authentication, quotas, expiration, and audit logging rather than publishing the upstream key.

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Python Dependency Allows Unreviewed Package Updates

Content
View full analysis

Vulnerability Details

File Location: requirements.txt, line 1
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

Vulnerable Code Snippet:

text
deepdub

The installation documentation reinforces the unpinned installation behavior in SKILL.md, lines 44-52:

markdown
Install the official Deepdub Python SDK:

```bash
pip install deepdub

Or using uv (faster alternative):

bash
uv pip install deepdub
text

The dependency is imported and trusted at runtime in `deepdub_tts.py`, line 7:
```python
from deepdub import DeepdubClient

Technical Analysis

requirements.txt specifies the deepdub package without a version constraint, lock file, or integrity hash. Consequently, separate installations can resolve to different package versions. A newly published, compromised, or behaviorally incompatible release can be installed without any corresponding change to this audited project.

Python packages may execute code during installation, and imported package modules execute initialization code at runtime. The skill also passes DEEPDUB_API_KEY to DeepdubClient, so a compromised dependency executing in the same process could read that key, inspect other accessible environment variables, access files permitted to the invoking account, and perform network requests.

The audit found no evidence that the currently intended deepdub package is malicious. The vulnerability is the absence of reproducible version and integrity controls, which leaves future installations dependent on mutable upstream package state.

Attack Path

  1. A user follows the documented installation command or installs from requirements.txt.
  2. The package installer resolves the latest package release available under the deepdub name at that time.
  3. If the upstream account, release pipeline, package index, or reso ...[truncated 1004 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin deepdub to a reviewed, known-good version rather than resolving the latest release:
    text
    deepdub==<reviewed-version>
    
  • Generate a reproducible lock file that pins all transitive dependencies.
  • Require package hashes, for example through a hash-locked requirements file used with:
    bash
    pip install --require-hashes -r requirements.txt
    
  • Update SKILL.md so documented installation commands use the locked dependency file instead of pip install deepdub.
  • Review changelogs and source changes before updating the pinned version, and run dependency vulnerability and provenance checks in CI.
  • Install and execute the skill as an unprivileged account in an isolated environment with minimal filesystem and network access.
  • Expose only the environment variables required by the skill, avoiding unrelated credentials in the same process environment.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill requests environment variables and writes media files, but the declared permission model is only described informally in prose rather than enforced through a machine-readable tool scope such as permissions or allowed-tools. This creates a real policy gap: a runner or reviewer may not be able to reliably constrain what the skill can access, increasing the chance of overbroad environment exposure or unintended file writes if execution controls depend on explicit scope declarations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The markdown explicitly sets DEEPDUB_LOCALE to default to en-US, which is a language/locale choice presented without any user choice mechanism or justification. Under the policy rule, forcing a specific locale without opt-in can be a natural-language policy violation even when expressed as documentation.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency is unpinned, so installs may pull whatever version is current at install time. That creates supply-chain risk: a malicious or compromised upstream release, or an unexpected breaking change, could be introduced into the skill without review, affecting environments that build or deploy it later.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
deepdub

Static analysis

No suspicious patterns detected.