Qwen3 Tts Mlx

Security checks across malware telemetry and agentic risk

Overview

This is a coherent local text-to-speech skill, but users should only use its voice-cloning feature with permission.

Install only if you are comfortable with the Python/Homebrew dependencies and MLX model downloads. Use voice cloning only with voices you own or have explicit permission to use, avoid impersonation or deceptive synthetic speech, and treat reference audio and transcripts as sensitive personal data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly documents voice cloning from reference audio but provides no consent, impersonation, or privacy warning. In context, this makes misuse easier by normalizing cloning workflows without safeguards, increasing the risk of unauthorized voice impersonation and handling of sensitive biometric voice data.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal