Back to skill

Security audit

Beware Piper Tts Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a local Piper text-to-speech guide with some confusing dependency wording, but no artifact-backed hidden behavior or malicious actions.

Before installing, treat this as a local command-running TTS skill: verify any setup scripts or commands you use, expect dependency/model downloads during first setup, and do not add an API key unless your agent platform separately requires one.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The documentation makes materially conflicting trust and dependency claims: it advertises 'zero API key / no networking' while later requiring an LLM API and API_KEY configuration. This can mislead users about the skill's true operational and data-exposure characteristics, causing them to enable or run it under incorrect security assumptions.

Missing User Warnings

Low
Confidence
76% confidence
Finding
The skill instructs users or agents to run local shell scripts that install software, download voice assets, and write MP3 files, but it does not foreground the security implications of command execution or local filesystem changes. In agent contexts with exec enabled, this can normalize running potentially unreviewed scripts and increase the chance of unintended system modification.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.