Minimax Tts Cn

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed MiniMax text-to-speech skill that can optionally send generated voice messages to Telegram or Feishu, with no evidence of hidden or destructive behavior.

Install only if you are comfortable sending TTS text to MiniMax and, when Telegram credentials are configured, sending generated audio and captions to the configured Telegram chat. Use --generate-only when you want local audio only, protect the .env credentials, and delete generated audio files if they contain sensitive content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The script uploads generated audio and optional caption text to Telegram automatically once invoked, using a configured default target if provided. In an agent context, this can cause unintended disclosure of sensitive user content to an external third party without an explicit per-send confirmation or clear runtime warning.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal