Back to skill

Security audit

Microsoft Edge TTS

Security checks across malware telemetry and agentic risk

Overview

This is a coherent online text-to-speech skill, but users should remember that text is processed by Microsoft Edge's online TTS service.

Install only if you are comfortable sending the text you convert to Microsoft Edge's online TTS service and running the referenced npm package. Avoid using it for passwords, secrets, regulated data, or confidential documents unless you have reviewed and accepted that data handling.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill describes a cloud-backed TTS capability but does not clearly warn that submitted text is transmitted to Microsoft's online service. This can lead users or upstream agents to send sensitive or confidential text off-device without informed consent, creating a real privacy and data-handling risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.