Back to skill

Security audit

OctoASR

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent local audio transcription setup guide, but users should notice that the optional cloud fallback is no longer fully offline.

Install only if you are comfortable adding the Mininglamp-AI Homebrew tap and running a local transcription service. Use the recommended local-only configuration for private audio; enabling the OpenAI fallback means audio may be processed by a cloud provider when local transcription fails.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill recommends a hybrid configuration where local transcription silently falls back to OpenAI if the local CLI fails, but it does not prominently warn users that audio content may then be sent to a third-party cloud provider. This creates a privacy and data-governance risk because users may believe the setup is fully offline and could unintentionally transmit sensitive voice data externally.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.