Back to skill

Security audit

Dlazy Elevenlabs Stt

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed dLazy cloud transcription wrapper that uploads chosen audio for speech-to-text and stores a dLazy API key locally if the user logs in.

Before installing, understand that audio files or URLs you provide will be processed through dLazy infrastructure, not only locally. Use npx if you do not want a persistent global CLI install, and rotate or revoke the dLazy API key if you no longer need the skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill is presented as an ElevenLabs speech-to-text capability, but the documentation discloses that prompts and local media files are actually sent to dLazy-controlled infrastructure. This is a material data-flow mismatch that can mislead users about where sensitive audio is processed and stored, increasing privacy, compliance, and trust risks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.