Back to skill

Security audit

Deepdub TTS

Security checks across malware telemetry and agentic risk

Overview

This skill appears to do what it claims: it sends text to Deepdub to generate an audio file, with no hidden persistence or unrelated access found.

Install only if you are comfortable sending synthesized text to Deepdub. Use your own Deepdub API key and voice prompt ID for private or production use, avoid sensitive text with the shared trial credentials, and consider pinning the Deepdub SDK version in controlled environments.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Unpinned Dependencies

Low
Category
Supply Chain
Content
deepdub
Confidence
95% confidence
Finding
deepdub

VirusTotal

47/47 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.