SOTA Zero-shot Voice Cloning TTS

Security checks across malware telemetry and agentic risk

Overview

This instruction-only voice cloning skill is purpose-aligned, but users should treat uploaded voice samples and text as sensitive data sent to an external MOSS service.

Install only if you trust the MOSS service and configured base URL. Do not submit private recordings, sensitive text, or voices you lack permission to clone; prefer an existing voice_id when available and use a revocable API key.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly supports using a local audio path and uploading that file to an external voice service, but it does not warn the operator or user that local content will leave the local environment. This creates a real privacy and data-handling risk because users may provide sensitive recordings or filesystem-sourced audio without informed consent, and the voice-cloning context increases sensitivity due to biometric voice data exposure.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal