Back to skill

Security audit

声音克隆 ElevenLabs Voice Clone

Security checks across malware telemetry and agentic risk

Overview

This voice-cloning skill is transparent about using a cloud CLI, but it needs Review because it uploads sensitive voice data without consent or impersonation safeguards and its docs contain command/output mismatches.

Review carefully before installing. Use this only with voice samples you own or have explicit permission to clone, and assume local audio paths may be uploaded to dLazy-hosted infrastructure. Prefer per-invocation credentials or rotate/revoke the saved API key if you stop using the service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The documented output format claims this voice-cloning skill returns an image URL and image MIME type, which is inconsistent with the skill’s stated purpose. This can mislead an agent or user into mishandling outputs, building incorrect downstream automation, or trusting malformed results from a remote service without proper validation.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The usage and error-handling sections reference an undeclared `--prompt` parameter instead of the documented voice-clone inputs like `--audio_url`, `--name`, and `--description`. This inconsistency can cause agents to invoke the wrong command shape, mis-handle failures, or pass unintended data to the backend, increasing the chance of unsafe or erroneous execution.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
This skill enables instant voice cloning from an uploaded human voice sample yet provides no warning, gating, or policy guidance around consent, impersonation, or fraud risks. In this context, the omission is dangerous because voice cloning is highly sensitive and can facilitate impersonation, social engineering, non-consensual biometric misuse, and reputational harm if agents or users are not explicitly constrained.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
This skill handles highly sensitive biometric data but does not warn about consent, impersonation risk, retention, or privacy implications of uploading a voice sample to third-party infrastructure. In the context of voice cloning, omission of these safeguards is dangerous because users may upload another person’s voice or their own biometric data without informed consent or understanding of how it will be stored and used.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.