Back to skill

Security audit

Azure Voicelive Tool Free

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Azure VoiceLive coding guide that uses cloud voice processing as advertised, with no hidden execution or persistence found.

Install only if you intend to build Azure VoiceLive examples. Voice audio, transcripts, and prompts may be sent to Azure when you run the sample code, so avoid recording sensitive or regulated conversations unless you have approval and understand your Azure account's data handling settings.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
76% confidence
Finding
The skill encourages microphone audio capture, network transmission over WebSocket, and cloud processing using API credentials, but it omits an explicit privacy warning about sending potentially sensitive voice data to Azure. In an agent setting, this increases the risk that users enable recording or transmit regulated content without informed consent or awareness of data handling implications.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.