Voice messaging setup

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says: it sets up local speech-to-text and Edge-based text-to-speech for OpenClaw voice messages, with a privacy note for cloud TTS use.

Install this if you are comfortable with faster-whisper downloading packages/models locally and with generated voice-reply text being synthesized through Edge/Microsoft TTS. For sensitive conversations, disable automatic TTS or use a local TTS provider if available.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill enables automatic Edge TTS replies but does not clearly disclose that reply text may be sent to an external Microsoft/Bing-backed network service for synthesis. This creates a real privacy and data-handling risk because users may unknowingly transmit message content off-host when voice replies are enabled.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal