Back to skill

Security audit

Agentvibes Voice Skill Free

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a TTS instruction document, but it asks users to configure an unclear API key and allows automatic downloads or installs without enough scoping.

Review this before installing if you operate in a restricted or sensitive environment. Do not export any API key unless you know which agent platform needs it and why. Expect first-use network downloads from HuggingFace and possible local model caching; prefer manual installation with verified Piper voice files if supply-chain control matters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The skill documentation is internally inconsistent: it markets the tool as free/offline and only needing Piper voice downloads, yet also declares an LLM API as mandatory and instructs users to export an API key. This can mislead operators into unnecessarily provisioning secrets or misunderstanding when network/API use occurs, increasing the chance of credential exposure and unsafe deployment assumptions.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill states that first-time voice selection will automatically download model files from HuggingFace, but it does not present this as a prominent warning before execution. In a skill with exec capability, silent or poorly disclosed network retrieval can violate offline expectations, trigger unintended outbound connections, and introduce supply-chain risk from externally fetched artifacts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.