Back to skill

Security audit

Cloudflare Whisper Worker

Security checks across malware telemetry and agentic risk

Overview

The skill appears to do what it says—send a chosen audio file to a Cloudflare Worker for transcription—but users should know it uploads audio and uses a bearer token.

This skill is reasonable for its stated purpose if you trust the Cloudflare Worker endpoint. Before using it, confirm the audio file is appropriate to upload, keep WHISPER_WORKER_TOKEN secret, avoid custom URLs unless trusted, and ensure required local tools such as curl and jq are available.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.