Back to skill

Security audit

Skill

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only text-to-speech skill whose disclosed behavior fits its purpose, with a note that some voices may require HuggingFace downloads before offline use.

Before installing, be aware that some Piper voices may need to be downloaded from HuggingFace before they work offline. Review the separate AgentVibes runtime before allowing update or cleanup commands, and use cleanup after sessions where spoken output may contain sensitive information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill repeatedly emphasizes that it is 'offline' and requires 'no account,' but later states that voices are downloaded from HuggingFace. That mismatch can mislead users into assuming no network access or external disclosure occurs, when first-time voice downloads may contact a third-party service and expose metadata such as IP address, timing, requested model names, or enterprise egress details.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.