ops-voice

Fail

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The setup sub-command implements a broad credential harvesting routine. It systematically scans sensitive files and system utilities to extract API keys:
  • Accesses shell configuration and environment files: ~/.zshrc, ~/.bashrc, ~/.zprofile, and ~/.envrc.
  • Iterates through all available projects and configurations in the Doppler secret manager to retrieve computed secrets.
  • Queries the Dashlane password manager CLI (dcli) for credentials matching specific service names.
  • Attempts to extract passwords directly from the macOS system Keychain using the security find-generic-password utility.
  • [COMMAND_EXECUTION]: The skill is highly vulnerable to command injection. Input variables such as PHONE, PROMPT, TEXT, and AUDIO_FILE are extracted from $ARGUMENTS and interpolated directly into Bash scripts and curl command payloads without sanitization or escaping. An attacker could provide input containing shell metacharacters (e.g., $(...) or backticks) to execute arbitrary code on the host system.
  • [DATA_EXFILTRATION]: While the skill claims to validate keys against official service providers, the automated harvesting of secrets from password managers and system keychains into the agent's execution context creates a significant risk of data exfiltration if the agent session is compromised or logs are intercepted.
  • [INDIRECT_PROMPT_INJECTION]: The skill represents a vulnerable surface for indirect attacks as it ingests untrusted data from arguments and local files for processing in high-privilege operations (shell execution and network requests).
  • Ingestion points: User-provided strings in $ARGUMENTS and local file paths for audio transcription.
  • Boundary markers: None. The script lacks delimiters or instructions to prevent the interpreter from executing embedded commands within the input.
  • Capability inventory: The skill has access to Bash execution, sensitive file reading, and outbound network operations via curl.
  • Sanitization: Absent. Data is used directly in shell command construction.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Oct 8, 2026, 09:46 PM