Back to skill

Security audit

uydi-voice

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Uydi voice-platform CLI that uses OAuth to create, clone, manage, and synthesize voices under the user's account.

Before installing, understand that this skill can spend Uydi credits, upload an audio sample for authorized voice cloning, save generated audio locally, list account history, and permanently delete Uydi voices when explicitly commanded. Complete OAuth only on the expected Uydi site and use logout or the website to revoke access when no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/uydi.mjs:107