Back to skill

Security audit

Podcast Chaptering

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent podcast chaptering helper that uses files, optional API hosting, and external AI processing in ways that match its stated purpose.

Before installing, confirm you are comfortable sending podcast transcript content to an external AI provider when using AI chaptering. Use a scoped output directory for batch runs, protect any FastAPI deployment with authentication, and avoid processing confidential or unpublished material unless your provider and account settings meet your privacy requirements.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill sends uploaded transcript content to an external AI API via the OpenAI client, but the documentation does not prominently warn users that their uploaded data leaves the local environment. For podcast transcripts, this may expose unpublished content, sensitive internal discussions, personal data, or contractual material to a third-party processor without sufficiently informed consent.

VirusTotal

51/51 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.