VoiceMonkey

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward VoiceMonkey instruction skill for controlling Alexa devices with a user-provided token, with no hidden code or unrelated behavior found.

Install only if you trust the agent to use your VoiceMonkey token. Prefer Authorization headers over URL query tokens, keep the token private, rotate it if exposed, and require explicit confirmation before announcements, media playback, websites, routines, or flows, especially if Alexa routines control locks, alarms, purchases, or other high-impact devices.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal