Back to skill

Security audit

kesha-voice-kit

Security checks across malware telemetry and agentic risk

Overview

This is a local voice transcription and speech tool whose access and setup are disclosed and mostly match its purpose.

Install only if you want a local voice toolkit and are comfortable with a global Bun package plus local model downloads. Review the OpenClaw config snippets before applying them, especially transcript echoing and automatic TTS replies, and avoid routing unrelated files or private audio into the tool unintentionally.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger keyword list contains very broad terms such as "say," "privacy," and common audio/file-related words that may match ordinary conversations unrelated to this skill. In an agent environment, overbroad triggers can cause unintended invocation, unnecessary command execution or installation prompts, and accidental processing of local audio/files the user did not intend to route through this tool.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.