Vocal Chat

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says: it turns WhatsApp voice messages into local transcriptions and local voice replies, with no evidence of hidden data theft or persistence.

Install only if you want WhatsApp audio messages handled by an agent. Use it in chats where automated text and voice replies are acceptable, verify the referenced local speech tools are trusted, and check whether your setup stores temporary audio or transcripts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill automatically transcribes incoming WhatsApp audio and generates voice replies, but the description and instructions do not clearly warn users about this automatic processing behavior. That creates a privacy and consent risk because users may send voice notes expecting normal handling, while the system performs speech-to-text and voice synthesis without an explicit notice or opt-in.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal