Back to skill

Security audit

Axiomata Voice

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward text-to-speech helper, but users should know that spoken text may be sent to ElevenLabs and Telegram.

Install only if you are comfortable using ElevenLabs and Telegram for this workflow. Use revocable service credentials, prefer a dedicated Telegram bot, avoid sending secrets or regulated personal data as TTS input, and verify or add the missing Telegram delivery script before relying on that part of the skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explains required keys and functionality but does not clearly warn that user-provided text will be transmitted to ElevenLabs and potentially forwarded to Telegram. This creates a privacy and data-handling risk, especially if agents pass sensitive or regulated content into the skill without explicit user awareness.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.