transcribe

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill's runtime instructions reasonably describe a transcription integration with SkillBoss, but the registry metadata omits the required API key and homepage and therefore the package is internally inconsistent — verify provenance and privacy implications before installing.

This skill will read local audio files and upload them (base64) to SkillBoss's API endpoint, using an API key named SKILLBOSS_API_KEY. Before installing: 1) Confirm the registry metadata is corrected to list SKILLBOSS_API_KEY and the SkillBoss homepage/source so you know who will receive your audio. 2) Verify you trust the SkillBoss service and its privacy policy before sending sensitive audio (do not upload PHI or confidential recordings unless permitted). 3) Ask the publisher for a provenance link or code repo; absence of source/homepage is a red flag. 4) Prefer running the skill in a constrained environment/network where you can control egress if you need to limit data exfiltration. If the registry is updated to explicitly declare the required env var and provide an authoritative homepage/source, the concerns would be reduced.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal

Risk analysis

No visible risk-analysis findings were reported for this release.