Audio Content Generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent audio-generation helper that uses disclosed AI and ElevenLabs services, with no artifact-backed evidence of hidden behavior, exfiltration, persistence, or destructive actions.

Install only if you are comfortable sending the approved script text to Anthropic and ElevenLabs and paying any provider costs. Avoid using it for sensitive, proprietary, or regulated content unless those providers' data handling terms are acceptable to you.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill sends user-provided or model-generated content to ElevenLabs, but the upfront description does not clearly warn users that their content will be transmitted to a third-party service. This creates a real privacy and data-handling risk, especially if users provide sensitive, proprietary, or regulated content under the assumption that processing is local.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal