ops-voice
Fail
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The
setupsub-command implements a broad credential harvesting routine. It systematically scans sensitive files and system utilities to extract API keys: - Accesses shell configuration and environment files:
~/.zshrc,~/.bashrc,~/.zprofile, and~/.envrc. - Iterates through all available projects and configurations in the
Dopplersecret manager to retrieve computed secrets. - Queries the
Dashlanepassword manager CLI (dcli) for credentials matching specific service names. - Attempts to extract passwords directly from the macOS system Keychain using the
security find-generic-passwordutility. - [COMMAND_EXECUTION]: The skill is highly vulnerable to command injection. Input variables such as
PHONE,PROMPT,TEXT, andAUDIO_FILEare extracted from$ARGUMENTSand interpolated directly into Bash scripts andcurlcommand payloads without sanitization or escaping. An attacker could provide input containing shell metacharacters (e.g.,$(...)or backticks) to execute arbitrary code on the host system. - [DATA_EXFILTRATION]: While the skill claims to validate keys against official service providers, the automated harvesting of secrets from password managers and system keychains into the agent's execution context creates a significant risk of data exfiltration if the agent session is compromised or logs are intercepted.
- [INDIRECT_PROMPT_INJECTION]: The skill represents a vulnerable surface for indirect attacks as it ingests untrusted data from arguments and local files for processing in high-privilege operations (shell execution and network requests).
- Ingestion points: User-provided strings in
$ARGUMENTSand local file paths for audio transcription. - Boundary markers: None. The script lacks delimiters or instructions to prevent the interpreter from executing embedded commands within the input.
- Capability inventory: The skill has access to Bash execution, sensitive file reading, and outbound network operations via
curl. - Sanitization: Absent. Data is used directly in shell command construction.
Recommendations
- AI detected serious security threats
Audit Metadata