Back to skill

Security audit

Speechmatics

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Speechmatics connector that uses the OOMOL CLI with appropriate confirmation guidance for write actions.

Install this only if you intend to let Codex operate your Speechmatics account through OOMOL. Review payloads before approving transcription submissions, and be cautious with the fallback CLI install command because it runs a remote installer script.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description is overly broad: it directs the agent to use this skill for ANY Speechmatics request and whenever a task involves Speechmatics, without narrowing scope or requiring explicit user intent. This can cause inappropriate tool selection or unintended external actions, especially because the skill exposes both read and write operations and may steer the agent away from safer direct handling or clarification.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.