Pywayne Tts

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward text-to-speech skill with expected local audio tooling and optional Google TTS use, but users should avoid sending sensitive text through the remote TTS path.

Install ffmpeg, gtts, and any pywayne dependency only from trusted sources. Prefer the local macOS say path for private text when available, and do not send secrets, credentials, regulated data, or confidential content through gTTS unless you accept third-party processing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill documents use of Google TTS but does not clearly warn that provided text may be transmitted to a third-party network service when gTTS is used. In a TTS tool, users may submit sensitive prompts, credentials, or private content, so the omission can lead to unintended data disclosure rather than a purely cosmetic documentation issue.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal