Polyphone TTS

Security checks across malware telemetry and agentic risk

Overview

This skill is a purpose-aligned Chinese text-to-speech helper that sends text to SenseAudio using the user's API key, with no hidden install code or persistence found.

Install only if you are comfortable sending the text you synthesize and the selected cloned voice ID to SenseAudio. Protect the SENSEAUDIO_API_KEY, use only voices you are authorized to use, and avoid submitting sensitive or confidential text unless SenseAudio's terms and data handling are acceptable for your use case.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill instructs the agent to send user text and a cloned voice identifier to an external API using a bearer token, but it does not require explicit user-facing disclosure or consent before transmission. This can lead to unintended sharing of potentially sensitive text content and voice-linked identifiers with a third-party service.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal