surf-qml

Fail

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The narration.py script uses urllib.request.urlopen to download audio data from a remote server (defaulting to http://localhost:8000/v1/tts but configurable via the HORUS_TTS_URL environment variable). The downloaded content is written to the local filesystem as a .wav file.
  • [COMMAND_EXECUTION]: The skill makes extensive use of subprocess.run to interact with system utilities. This includes using xdotool for simulating keyboard and mouse input, ffmpeg for video recording, and ImageMagick's import for screenshots. Additionally, narration.py executes media players like ffplay or aplay to play downloaded audio files and can invoke a shell script (run.sh) from a different skill directory.
  • [DATA_EXFILTRATION]: The skill has the capability to capture screenshots and record video of the user's desktop or specific application windows. Furthermore, by interacting with the Linux AT-SPI (Accessibility Service Provider Interface) bus, the skill can programmatically inspect the element tree and metadata of all running GUI applications, potentially exposing sensitive information displayed on screen or within application structures.
  • [PROMPT_INJECTION]: The scenario_runner.py component executes automated testing steps defined in YAML or JSON scenario files. These scenarios can include instructions to type arbitrary text or press specific key combinations. If an agent is directed to process an untrusted scenario file, it could be used as an indirect prompt injection vector to execute commands by typing into a terminal window or interacting with sensitive applications.
  • [COMMAND_EXECUTION]: The skill employs dynamic loading techniques in narration.py by modifying sys.path at runtime. It inserts paths derived from environment variables (HORUS_OVERLAY_SRC, MEMORY_PROJECT_ROOT) and relative directory traversal to import internal modules such as voice. This pattern of loading code from computed paths can be exploited if the environment variables are manipulated.
Recommendations
  • HIGH: Downloads and executes remote code from: unknown (check file) - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 17, 2026, 06:36 AM
Security Audit — agent-trust-hub — surf-qml