qwen3-tts-local-inference

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent local text-to-speech tool, but users should only use its voice-cloning feature with consent.

Install only if you are comfortable running third-party Python packages and downloading large Hugging Face models. Use voice cloning only with explicit permission from the person whose voice is referenced, and avoid impersonation, fraud, harassment, or misleading audio.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly supports voice cloning from a short reference clip but provides no warning about consent, impersonation risk, or misuse controls. That omission can facilitate non-consensual voice cloning, social engineering, fraud, or harassment by making a high-risk capability appear routine and unrestricted.

VirusTotal

44/44 vendors flagged this skill as clean.

View on VirusTotal