Percept Ambient
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The skill `percept-ambient` is classified as suspicious due to its core functionality involving continuous ambient speech capture and transcription, which inherently handles highly sensitive personal data. While the `SKILL.md` explicitly states that data is stored locally and no audio is retained (only transcripts), the continuous processing of private conversations represents a significant privacy risk. Additionally, the skill exposes a local API and dashboard on `http://localhost:8960`, which, while intended for monitoring, introduces a potential attack surface for local privilege escalation or other vulnerabilities if not robustly secured. There is no evidence of intentional data exfiltration, malicious execution, or prompt injection attempts against the agent within the provided files, but the high-risk capabilities warrant a 'suspicious' classification.
