Back to skill

Security audit

ElevenLabs Open Account

Security checks across malware telemetry and agentic risk

Overview

This is a simple ElevenLabs signup and API-key guidance skill with disclosed links and no executable behavior.

Before installing, note that the signup link is an affiliate link. Create API keys only on ElevenLabs, treat them like passwords, avoid pasting them into chats or client-side apps, and use scopes or credit limits where available.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The skill advertises broad use for sign-up, API access, and connecting multiple bots without tightly scoped activation conditions. In an agent system, that can cause the skill to trigger in situations where the user did not clearly request account creation or credential-related guidance, increasing the chance of unnecessary account onboarding or sensitive-token handling flows.

Vague Triggers

Low
Confidence
72% confidence
Finding
The opening workflow says to use this skill whenever the user needs to open or sign up for an ElevenLabs account, but it does not clearly distinguish this from other ElevenLabs skills or require a precise user intent match. In multi-skill environments, ambiguous routing can lead the agent into account-creation or API-enablement steps prematurely, which is risky because those flows can expose users to credential creation and affiliate-driven navigation.

VirusTotal

54/54 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.