Back to skill

Security audit

Fish Audio

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only Fish Audio API skill, but users should only clone voices they are authorized to use.

Install only if you are comfortable using an AceDataCloud API token and sending text or reference-audio URLs to that provider. Use scoped or revocable credentials where possible, monitor usage costs, and clone voices only with clear permission from the speaker and in compliance with applicable laws.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly documents voice synthesis/cloning using a reference audio URL but provides no warning about consent, privacy, impersonation risk, or the need to use only authorized recordings. In a voice-cloning context, omission of these safeguards can enable misuse such as cloning another person's voice without permission or processing sensitive biometric-like voice data inappropriately.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.