Audio Transcribe

Security checks across malware telemetry and agentic risk

Overview

This skill appears to locally transcribe audio as advertised, with the main caution that enabled voice messages may become readable text.

Install this only if you want voice messages transcribed locally. Treat audio and resulting transcripts as sensitive, confirm where Clawdbot stores or displays transcripts in your environment, and be comfortable trusting the faster-whisper package and downloaded model files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill states that incoming voice messages are automatically transcribed, but provides no privacy notice, consent requirement, retention guidance, or warning about sensitive data exposure. Voice messages often contain personal, confidential, or regulated information, so silent or default transcription can create privacy, compliance, and trust risks even if processing is local.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal