This skill attempts to access sensitive credential files, uses deceptive branding, and lacks dependency version pinning, creating significant risks for credential theft and supply chain compromise.
npx skills add https://github.com/zxkane/audio-transcriberAccess to known credential file paths detected (seen 3 times in this file at lines 29, 146, 166)
~/.aws/credentials
The setup script installs dependencies without version pinning (e.g., flash-attn), which could lead to the execution of arbitrary code if the upstream package is compromised.
flash-attn==2.7.4.post1
Skill name or description references a well-known AI brand, which may suggest impersonation.
openai
Skill does not specify a license field. Specifying a license helps users understand usage terms.
[](https://mondoo.com/ai-agent-security/skills/github/zxkane/audio-transcriber/audio-transcribe)<a href="https://mondoo.com/ai-agent-security/skills/github/zxkane/audio-transcriber/audio-transcribe"><img src="https://mondoo.com/ai-agent-security/api/badge/github/zxkane/audio-transcriber/audio-transcribe.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/zxkane/audio-transcriber/audio-transcribe.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.