Back to skill

Security audit

AI Stem Splitter

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward hosted audio stem-splitting helper, with expected API-key and audio-upload behavior that users should treat as third-party processing.

Install this only if you are comfortable sending the chosen audio file, source URL, and related job metadata to AI Stem Splitter. Confirm each file or URL before submission, avoid private or internal URLs unless intended, protect the API key, and verify optional SDK packages before installing them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The documentation instructs users to send audio URLs and optionally receive webhook callbacks from an external third-party API, but it does not include any user-facing disclosure about data leaving the local environment. In a skill that processes potentially copyrighted, private, or sensitive audio, this omission can lead to unintended external data sharing and privacy/compliance issues.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.