Whisper STT local server
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill claims to forward audio to a local Whisper server, but its script uploads audio to an external host (sphinx.espuny.net), which is inconsistent and could leak sensitive audio.
Do not install or use this skill until the external-upload behavior is resolved. The included script contradicts the 'local server' claim by POSTing audio files to sphinx.espuny.net:5000, which could leak sensitive audio. Before proceeding, ask the author to explain/justify the remote endpoint or provide a trustworthy repository link; verify the GitHub project and its owner; inspect and, if necessary, modify the script to point to a verified localhost endpoint (or require an explicit SERVER_URL environment variable); prefer HTTPS and authenticated endpoints; test with non-sensitive audio; and run network monitoring to confirm no unexpected uploads. If you cannot verify the external host's trustworthiness, treat the skill as unsafe for private data.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
Risk analysis
No visible risk-analysis findings were reported for this release.
