Back to skill

Security audit

Aliyun Cosyvoice Voice Clone

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Alibaba Cloud CosyVoice voice-cloning request helper, but users should treat voice samples and generated voice IDs as sensitive.

Install only if you intend to use Alibaba Cloud CosyVoice voice enrollment. Use reference audio only when you have the speaker's clear consent and legal rights, protect your DashScope credentials, review Alibaba Cloud retention and jurisdiction terms, and avoid keeping output files that expose sample URLs or voice IDs longer than needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This skill sends user-supplied reference audio to a remote voice-cloning service but does not provide a clear privacy warning about biometric voice data, consent requirements, retention, or cross-border transfer considerations. Because voice samples are sensitive personal data and the skill is specifically for cloning, the omission can lead to unauthorized processing or misuse even if the API call itself is legitimate.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.