Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Transcrição e respostas em áudio em PTBR, Português Brasil - Brazillian portuguese transcription and audio answers

v2.0.2

Premium Portuguese-Brazilian voice interface with neural TTS and Claude AI integration. Features wav2vec2-large-xlsr-53-ptBR for excellent PT-BR understandin...

0· 83·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
Capability signals
Crypto
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Benign
high confidence
Purpose & Capability
Name/description (PT-BR ASR + Piper TTS + optional Claude) align with the included scripts, installer, and model downloads. Required artifacts (Piper binary, voice models, transformers/torch) are expected for the declared functionality and are the only notable external dependencies.
Instruction Scope
SKILL.md directs the agent to run the provided install.sh and process.sh and to use local models. Runtime scripts operate on audio files, write a voice config under ~/.openclaw/workspace, and only call the Anthropic API when ANTHROPIC_API_KEY is set. The skill does not request unrelated system files or unrelated credentials in the manifest.
Install Mechanism
install.sh downloads Piper from GitHub releases and model files from HuggingFace (expected for TTS models) and installs Python packages. These are legitimate sources but the installer runs system package installation (apt/brew) and pip installs without pinned versions in the installer. The installation will download large ML packages (torch/transformers) and write files under ~/.openclaw/workspace.
Credentials
The skill declares no required env vars; it documents an optional ANTHROPIC_API_KEY to enable Claude. No unrelated secrets or multiple unrelated credentials are requested. The scripts persist a small voice preference file in the workspace, which is consistent with the purpose.
Persistence & Privilege
The skill is not always-enabled and is user-invocable. It creates files under the user's workspace (~/.openclaw/workspace) and downloads binaries/models there. It does attempt to install system packages (may require sudo) but does not request system-wide configuration changes beyond installing software and creating its workspace.
Assessment
This skill appears to do what it claims, but review the following before installing: 1) Installation will download and install large ML packages (torch/transformers) and voice models (~hundreds of MB) and may invoke sudo to install system packages (ffmpeg, python3, pip) — expect significant disk, network, and CPU use. 2) The installer downloads Piper from GitHub and voice models from HuggingFace; check these sources if you have policy concerns about third-party models. 3) Providing ANTHROPIC_API_KEY enables sending user audio/text to Anthropic (external service); if you care about privacy, keep the key unset to use local/OpenClaw fallback. 4) Run python3 health_check.py after install to validate the setup in a controlled environment before exposing to users. 5) If you need stricter reproducibility or audits, inspect install.sh and the Python scripts (claude_adapter.py) and consider pinning pip package versions or installing in an isolated virtualenv/container.

Like a lobster shell, security has layers — review code before you run it.

audiovk97fsryxfza3aj8rd9m7qjam6n84nhjhaudio transcricao ptbr sotaque mensagem portugues brasil conversavk979p1ttvkh7aen4j2x6g1q0rn84nv5qaudio transcript transcricao ptbr portugues brasil sotaque expressoes mensagem conversavk97f682qq8vpm4mqn0dn4529d184njqybrvk97fsryxfza3aj8rd9m7qjam6n84nhjhbrasilvk97fsryxfza3aj8rd9m7qjam6n84nhjhexpressaovk97fsryxfza3aj8rd9m7qjam6n84nhjhgiriavk97fsryxfza3aj8rd9m7qjam6n84nhjhlatestvk973n2bdxgn6vrx2xxcqvyg0b184vn3ymensagemvk97fsryxfza3aj8rd9m7qjam6n84nhjhportuguesvk97fsryxfza3aj8rd9m7qjam6n84nhjhptbrvk97fsryxfza3aj8rd9m7qjam6n84nhjhtelegramvk97fsryxfza3aj8rd9m7qjam6n84nhjhttsvk97fsryxfza3aj8rd9m7qjam6n84nhjh

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments