Back to skill

Security audit

Audio Upload Aioz Stream Free

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward AIOZ audio upload skill, with expected remote upload and credential use clearly tied to its stated purpose.

Install only if you intend to upload selected audio files to AIOZ Stream. Provide AIOZ-specific keys only when needed, avoid storing them in broad shared environment variables, and review audio content or metadata before sending it to the remote service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Context-Inappropriate Capability

Low
Confidence
87% confidence
Finding
The skill’s documented authentication model uses AIOZ-specific headers, but it also instructs users to set a generic API_KEY environment variable. This ambiguity can cause users or agents to place sensitive credentials into an overly broad, commonly reused variable name that may be accidentally consumed, logged, or exposed by unrelated tools in the same environment.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs uploading local audio files and transmitting API credentials to a remote third-party endpoint without a clear upfront warning that file contents, metadata, and authentication material will leave the local environment. In an agent setting, insufficient disclosure can lead users to unintentionally exfiltrate sensitive recordings or embedded metadata to an external service they did not fully realize was involved.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.