Elevenlabs Transcribe

Security checks across malware telemetry and agentic risk

Overview

This is a coherent ElevenLabs transcription skill, with expected privacy considerations because chosen audio is processed by ElevenLabs.

Install only if you are comfortable sending the audio you choose to transcribe to ElevenLabs under your account. Use microphone mode intentionally, stop it when finished, protect ELEVENLABS_API_KEY, and verify the publisher if the “Official ElevenLabs skill” claim matters to your trust decision.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill encourages transcription from local files, microphone input, and remote URLs, but it does not clearly warn users that the audio content is transmitted to ElevenLabs for processing. This can lead users or downstream agents to send sensitive conversations, recordings, or live streams to a third-party service without informed consent, creating privacy and compliance risk.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal