Chattts

Security checks across malware telemetry and agentic risk

Overview

This appears to be a purpose-aligned text-to-speech skill, but users should know their input text is sent to a configured backend service.

Install only if you are comfortable with the text you convert to speech being sent to the configured TTS backend. Check CHATTTS_API_URL or the default endpoint before use, avoid sending secrets or sensitive personal data, and prefer a backend you operate or explicitly trust.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The script takes arbitrary user-supplied text and transmits it to a backend HTTP service without any explicit notice, consent flow, or indication to the user that their prompt leaves the local agent boundary. This creates a privacy and data-handling risk, especially because the default endpoint is a hard-coded private-network address, so users may assume processing is fully local when it may be handled by another service on the network.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal