ttsCN
Fail
Audited by Snyk on Aug 19, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.95). The skill contains examples and runtime rules that ask for API keys and show embedding secrets directly into shell commands/environment assignments (e.g. inline TENCENT_SECRET_ID="xxx" python3 ...), which would require an LLM to accept and reproduce secret values verbatim in generated output.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). In scripts/backends/cosyvoice.py, the runtime ingest path takes the user-provided input text chunks and submits them to DashScope via SpeechSynthesizer.streaming_call, then parses the service-emitted websocket messages in on_event/_extract_words to build word_boundaries.
Issues (2)
W007
HIGHInsecure credential handling detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata