Back to skill

Security audit

Ai Voice Cloning

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate voice-generation helper, but it sends user-provided text and media URLs to inference.sh and suggests a remote CLI installer.

Install only if you trust inference.sh and are comfortable with its CLI installation and login flow. Prefer the manual checksum-verified install path if supply-chain risk matters, and do not submit secrets, private scripts, regulated data, non-public media URLs, personal voice samples, portraits, or copyrighted content unless you have permission and accept the provider’s data handling terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list includes broad phrases such as 'narration', 'natural voice', and 'voice ai', which can cause the skill to activate in contexts not specifically requesting this tool. Over-broad invocation increases the chance of unintended remote processing of user text or media-related tasks, especially because the skill can chain into adjacent capabilities like media merging and avatar generation.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The quick-start and examples encourage users to submit text and media URLs to inference.sh without a clear warning that this data is sent to a remote third-party service. This can lead users to unknowingly transmit sensitive scripts, copyrighted content, private URLs, or personal media to external infrastructure.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.