Back to skill

Security audit

Agentvibes Skill

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed text-to-speech workflow guide whose file and command examples are aligned with audio generation, with no hidden persistence, exfiltration, or destructive behavior found.

Before installing, confirm you actually use AgentVibes and understand that the examples may run local scripts, process whole input directories, write audio files, and use an AGENTVIBES_LICENSE environment variable. Use dedicated output folders and avoid putting license values directly in scripts or shared logs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The activation scope is described in a broad, catch-all way that effectively claims coverage over many loosely related enterprise/TTS scenarios without clear boundaries. In an agent ecosystem, ambiguous scope can cause the skill to trigger in unintended contexts and then suggest or execute commands under `exec`, increasing the chance of unsafe or irrelevant command execution.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill includes executable examples that perform batch processing and write output to the filesystem, but it does not warn users that these commands create or overwrite files and may process entire directories. In an agent with `exec` capability, this raises the risk of unintended file modification, resource consumption, or destructive writes if the examples are adapted or auto-run without adequate confirmation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.