Back to skill

Security audit

Fn Ime Voice Switch

Security checks across malware telemetry and agentic risk

Overview

This is a macOS setup guide for switching input methods with Hammerspoon; it asks for sensitive permissions, but they match the stated automation purpose.

Before installing, review the exact Hammerspoon init.lua you plan to run, especially because the referenced template is missing from this artifact. Only grant Hammerspoon Accessibility and Input Monitoring if you trust Hammerspoon and the script, and remove those macOS privacy permissions when you no longer need the automation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs users to grant Hammerspoon both Accessibility and Input Monitoring permissions, which together provide broad capability to observe input events and control the UI. Although those permissions are functionally required for the described automation, the instructions do not explicitly warn users about their scope, associated privacy risk, or the need to trust the app and limit use to this automation scenario.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.