Back to skill

Security audit

ai-podcast-generator

Security checks across malware telemetry and agentic risk

Overview

This podcast skill is not clearly harmful, but it asks users to enable a broad paid SkillBoss API gateway that goes well beyond podcast audio generation.

Install only after reviewing the remote SkillBoss setup and deciding whether you are comfortable giving your agent a paid SkillBoss key that may unlock many non-podcast APIs. Use a restricted key or billing limits if available, and require explicit confirmation before sending scripts or using any scraping, social, search, email, or other non-podcast capability.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill is marketed as a narrowly scoped podcast generator, but its setup explicitly provisions access to hundreds of unrelated APIs and capabilities. That scope mismatch can cause agents or users to grant a much broader trust boundary than intended, increasing the chance of unnecessary data exposure or misuse through unrelated services.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The recommended models are largely general-purpose chat LLMs, which do not align with the stated function of generating podcast audio from scripts. This mismatch can mislead agents into routing sensitive content to inappropriate third-party models and obscures what service is actually being used for audio generation.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
Advertising scraping, social data, search, and email in a podcast-generation skill introduces unjustified high-risk capabilities unrelated to the user-facing purpose. In context, this broadens the operational scope and could encourage agents to invoke sensitive external actions under the cover of a benign audio workflow.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The invocation guidance uses broad language that can trigger the skill for generic 'AI podcast' requests without clarifying boundaries, inputs, or whether external transmission will occur. Overbroad activation raises the likelihood that an agent will invoke this third-party integration unnecessarily and send user data off-platform.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The 'When To Use' section lists ambiguous conditions that lack constraints on content type, model choice, or external data handling. This can cause accidental invocation in situations where users did not intend to use a third-party multi-service gateway, creating avoidable privacy and governance risk.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The setup instructions encourage one-command enablement of a large third-party platform but omit warnings that user prompts and other data may be transmitted to a broad external service with many unrelated capabilities. This undermines informed consent and increases the risk of oversharing sensitive data during normal agent use.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.