Security audit
Cloudflare Whisper Worker
Security checks across malware telemetry and agentic risk
Overview
The skill appears to do what it says—send a chosen audio file to a Cloudflare Worker for transcription—but users should know it uploads audio and uses a bearer token.
This skill is reasonable for its stated purpose if you trust the Cloudflare Worker endpoint. Before using it, confirm the audio file is appropriate to upload, keep WHISPER_WORKER_TOKEN secret, avoid custom URLs unless trusted, and ensure required local tools such as curl and jq are available.
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
