Back to skill

Security audit

Gladia Pre Recorded Transcription

Security checks across malware telemetry and agentic risk

Overview

This appears to be a purpose-aligned transcription skill, with the main user consideration being that audio may be sent to Gladia for processing.

Before installing, confirm you are allowed to share any audio or URLs you transcribe with Gladia. Avoid using it for confidential, regulated, or highly personal recordings unless the provider's retention, compliance, and privacy terms meet your needs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly instructs users to provide local file paths, URLs, or binary file objects to a third-party transcription service, but it does not clearly warn that audio content will leave the local environment and may contain sensitive data. This creates a real privacy and data-governance risk, especially for recordings containing PII, confidential business discussions, or regulated content.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.