Back to skill

Security audit

Willow Inference Server

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Willow ASR/TTS helper skill, but users should only send audio or text to a Willow server they trust.

Install only if you intend to use a Willow server for speech processing. Before running the setup script, review the upstream repository. Configure WILLOW_BASE_URL to a server you control or explicitly trust, preferably local, because audio recordings and supplied text may be logged or retained by that server.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The skill instructs users to upload local audio files to a server endpoint without any explicit warning that recordings may contain sensitive personal or business information. Even though the server is described as local, the configured host can be remote or misconfigured, so the omission can lead to unintended disclosure of sensitive audio data.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.