Back to skill

Security audit

Agentvibes Voice Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a TTS helper, but its offline/no-account claims conflict with later API key and network requirements, so users should review its data and network behavior before installing.

Install only if you are comfortable with network access for voice downloads and possible API-backed features. Avoid using sensitive text with translation or cloud/provider modes unless you have confirmed where the text is sent, and check cache locations before using cleanup commands.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The skill documentation makes conflicting claims about being 'free/offline' while later sections describe API keys, API connectivity, and network-dependent operations. This can mislead users and downstream agents into making unsafe trust decisions about data handling, network egress, and credential requirements, increasing the chance that sensitive text is sent externally without informed consent.

Intent-Code Divergence

Low
Confidence
88% confidence
Finding
The FAQ frames network use as a one-time initial voice download, but later sections normalize recurring API/network failures, implying broader ongoing connectivity than advertised. This inconsistency can cause users to underestimate external communication and privacy exposure, especially when processing sensitive text for synthesis or translation.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The documented cleanup command removes cached audio files but does not prominently warn that local user-generated or workflow-relevant audio artifacts will be deleted. In agentic or automated environments, such a command can cause unintended data loss, erase evidence needed for audit/debugging, or disrupt dependent workflows.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill states that voice files are automatically downloaded from HuggingFace without a prominent warning about external network access and transfer of metadata or request context. In practice, this can violate user expectations for offline use and may expose environment details or operational behavior to a third party.

Static analysis

No suspicious patterns detected.