TencentCloud TTS

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Tencent Cloud text-to-speech skill that needs cloud credentials and sends requested text to Tencent to create local audio files.

Install only if you intend to use Tencent Cloud TTS. Use a Tencent Cloud key limited to speech synthesis, avoid placing secrets in shared shells or logs, rotate keys if exposed, do not submit confidential or regulated text unless Tencent Cloud processing is acceptable, and choose output filenames that will not overwrite important files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger description is broad enough to match common user requests about speech, audio generation, or TTS, which can cause the skill to activate unexpectedly. Mis-triggering is dangerous because it may route user content to an external cloud provider and create files without sufficiently explicit user intent, increasing privacy and data-handling risk.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The document instructs users to configure cloud API secrets in environment variables but provides little warning about credential exposure, secret lifecycle management, or the privacy implications of sending text to a third-party TTS service. This is risky because users may mishandle credentials or submit sensitive text without understanding that it leaves the local environment.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal