Back to skill

Security audit

声音克隆 通义 Qwen Audio Clone

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly transparent about using a hosted voice-cloning API, but it handles sensitive voice cloning without consent guardrails and makes a questionable claim about API key file permissions.

Review this before installing. Only use it with your own voice or a voice you have explicit permission to clone, avoid uploading sensitive recordings unless you accept dLazy hosting/processing them, and prefer DLAZY_API_KEY per invocation if you do not want a persistent local API key file.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
This skill enables voice cloning from an uploaded sample but provides no consent, identity, or authorization warning. In this context, omission of safeguards is dangerous because it normalizes cloning another person's voice and can facilitate impersonation, fraud, or non-consensual synthetic media generation through an easy-to-use hosted API workflow.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.