Back to skill

Security audit

录音转写 Fun ASR

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed cloud transcription skill that uploads user-selected audio to dLazy and stores an API key locally, with no evidence of hidden or destructive behavior.

Install only if you are comfortable using dLazy's hosted service for transcription. Confirm that any audio you pass to --audio_url may be uploaded, prefer npx if you do not want a global CLI, and rotate or revoke the stored API key if you stop using the service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Low
Confidence
91% confidence
Finding
The trigger keyword `fun-asr` is broad and lacks clear scope constraints, so an agent may invoke this skill in loosely related contexts whenever transcription or ASR is mentioned. In this skill, invocation can lead to network requests, authentication handling, and possible upload of local audio paths to external services, which increases the chance of unintended data disclosure or unnecessary third-party API usage.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.