Back to skill

Security audit

Voice AI Agent Engineering

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only voice-agent design guide with real privacy and AI-disclosure considerations, but it contains no hidden code, install-time privileges, or automatic actions.

Safe to install as a reference skill, but do not treat it as production compliance approval. Before deploying a real voice agent, confirm AI-disclosure, call-recording, telemarketing, healthcare, payment, and data-retention requirements for each jurisdiction; scope CRM/API access tightly; avoid sending card data or unnecessary sensitive data through LLMs; and define human escalation and opt-out paths.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The README encourages building production voice agents for phone calls, outbound sales, healthcare, and customer service, but its framing can normalize deployment of systems that process call audio, PII, and potentially regulated data without prominently surfacing consent, recording, privacy, and telemarketing constraints. Although it briefly mentions compliance checklists, the promotional and quick-start sections do not warn users that unlawful call recording, autodialing, or handling sensitive data without proper controls can create legal and privacy harm.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill repeatedly recommends call recording, transcript logging, and CRM logging, but it does not present a consistent, default upfront warning that these privacy-impacting behaviors may occur. In voice and telephony contexts, silent recording or logging of personal data can create compliance and privacy exposure, especially across consent-sensitive jurisdictions.

Natural-Language Policy Violations

High
Confidence
96% confidence
Finding
The guidance says 'Never say "I'm an AI" unprompted' unless required by law, which encourages non-disclosure by default and can conflict with organizational policy, contractual obligations, or emerging AI transparency laws. In customer service and regulated calling contexts, this can mislead users about who they are interacting with and increase legal, reputational, and trust risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.