surf-qml
Fail
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
narration.pyscript usesurllib.request.urlopento download audio data from a remote server (defaulting tohttp://localhost:8000/v1/ttsbut configurable via theHORUS_TTS_URLenvironment variable). The downloaded content is written to the local filesystem as a.wavfile. - [COMMAND_EXECUTION]: The skill makes extensive use of
subprocess.runto interact with system utilities. This includes usingxdotoolfor simulating keyboard and mouse input,ffmpegfor video recording, and ImageMagick'simportfor screenshots. Additionally,narration.pyexecutes media players likeffplayoraplayto play downloaded audio files and can invoke a shell script (run.sh) from a different skill directory. - [DATA_EXFILTRATION]: The skill has the capability to capture screenshots and record video of the user's desktop or specific application windows. Furthermore, by interacting with the Linux AT-SPI (Accessibility Service Provider Interface) bus, the skill can programmatically inspect the element tree and metadata of all running GUI applications, potentially exposing sensitive information displayed on screen or within application structures.
- [PROMPT_INJECTION]: The
scenario_runner.pycomponent executes automated testing steps defined in YAML or JSON scenario files. These scenarios can include instructions totypearbitrary text or press specifickeycombinations. If an agent is directed to process an untrusted scenario file, it could be used as an indirect prompt injection vector to execute commands by typing into a terminal window or interacting with sensitive applications. - [COMMAND_EXECUTION]: The skill employs dynamic loading techniques in
narration.pyby modifyingsys.pathat runtime. It inserts paths derived from environment variables (HORUS_OVERLAY_SRC,MEMORY_PROJECT_ROOT) and relative directory traversal to import internal modules such asvoice. This pattern of loading code from computed paths can be exploited if the environment variables are manipulated.
Recommendations
- HIGH: Downloads and executes remote code from: unknown (check file) - DO NOT USE without thorough review
Audit Metadata