Voice Extractor

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill does what it claims, but users should avoid pasting sensitive private communications unless they are comfortable sharing them with the agent.

Before installing or using it, redact passwords, API keys, client details, regulated personal data, and third-party private content. Use samples you own or are authorized to share, and start with minimized or anonymized excerpts if the agent runs in a cloud environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly solicits emails, Slack messages, transcripts, and other private communications, which commonly contain personal, confidential, or third-party data. It provides no warning to sanitize sensitive content, obtain consent from other participants, or avoid regulated data, creating a real privacy and data-handling risk in normal use.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal