Back to skill

Security audit

Xiaomi-MiMo-V2-TTS

Security checks across malware telemetry and agentic risk

Overview

This is a normal cloud text-to-speech skill, but users should know their text is sent to Xiaomi's API.

Install only if you are comfortable sending synthesis text and optional context to Xiaomi MiMo. Use a dedicated revocable API key, avoid secrets or regulated/confidential content, and verify the install slug/publisher before use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill requires an API key and uses a third-party endpoint, but it does not clearly warn that input text and optional context are transmitted off-device to Xiaomi's service. This is a privacy and data handling issue because users may assume text is processed locally and may submit sensitive content.

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The script sends user-provided text and optional contextual user_text to a third-party cloud TTS service without any explicit warning, consent flow, or privacy notice at the point of use. In an agent-skill context, users may not realize that potentially sensitive content is leaving the local environment, which can lead to unintended disclosure of private or regulated data.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.