Back to skill

Security audit

speack2u

Security checks for vulnerabilities and agentic risk

Overview

This TTS preference skill is purpose-aligned, but it should be reviewed because it tells the agent to persist learned voice preferences by updating its own skill file.

Install only if you are comfortable with the skill learning voice-output preferences over time and persisting them into the skill instructions. Before use, prefer explicit confirmation for any saved preference and periodically review or clear the Voice, Style, Spoken Text, and Avoid sections.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Self-Modification

High
Category
Rogue Agent
Confidence
86% confidence
Finding

The file explicitly instructs the agent to consult this document when deciding whether to update SKILL.md, which creates a self-modification pathway. Even though the content appears benign and scoped to TTS preferences, allowing a skill to influence updates to its own instruction file can enable persistence of user-driven or adversarially injected preferences, and can become dangerous if other controls do not strictly validate what may be written.

Content

Scanner excerpt · criteria.md (reported line 3)May include surrounding context.

md
# Criteria for Voice Preferences / 语音偏好判断标准

Reference only — consult when deciding whether to update SKILL.md.
仅供参考 — 决定是否更新 SKILL.md 时查阅。

## When to Add / 何时添加

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill’s operational scope is overly broad: it says it will 'auto-evolve' and 'learn' from user feedback without clear boundaries on what data is observed, when adaptation occurs, or what actions are permitted. In a preference-learning skill, ambiguous scope can lead to unintended collection or retention of user behavioral signals and unexpected modification of TTS behavior beyond the user’s informed expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill indicates it will observe user feedback over time and fill preference sections, but it does not clearly warn the user that their interactions may be monitored for preference extraction and persisted. This creates a transparency and consent problem: users may unknowingly disclose sensitive traits or communication preferences that become stored configuration, which is especially risky in a cross-session adaptive system.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The document is explicitly bilingual in English and Chinese and includes a locale-specific TTS voice example (en-GB-SoniaNeural) plus Chinese-only example text, but it does not state that language choice should be driven by user preference or that the skill is limited to these locales. This can create a natural-language policy concern if the skill behavior implicitly privileges specific languages/locales without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.