Back to skill

Security audit

Tts Voice Ai

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward MiniMax text-to-speech skill, with normal privacy and consent cautions for remote TTS and cloned voice use.

Install only if you are comfortable using a MiniMax API key and sending the text you convert to MiniMax for processing. Do not submit secrets, regulated personal data, or confidential business text unless that provider use is approved for your situation, and use cloned or custom voices only with clear permission from the voice owner.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill clearly instructs users to send arbitrary text to a third-party TTS provider but does not disclose that prompts and content will leave the local environment. This creates a privacy and data-handling risk because users may submit sensitive, proprietary, or regulated text under the assumption the tool is local-only.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The voice cloning section encourages use of cloned voices without any warning about consent, impersonation, or legal/ethical restrictions. This can facilitate misuse such as non-consensual voice replication, fraud, harassment, or deceptive content generation, especially because the feature is presented as a normal workflow.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The tool transmits user-supplied text to a third-party TTS API, but it does not provide an explicit warning or consent step before sending potentially sensitive content off-host. In a skill context, users may assume local processing and unknowingly submit secrets, personal data, or confidential text to an external service.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.