agentskill.sh
secured
sherpa-onnx-tts
Local text-to-speech via sherpa-onnx (offline, no cloud)
安全评分
这个标签页按审计报告样式展示检测范围、问题列表和源片段。
高危 / 中危 / 低危
检测类别
指令边界文件系统写入网络引用平台安装流程
安全问题
中危
File Access
第 66 行
Access to hidden dotfiles in home directory
1. Download the runtime for your OS (extracts into `~/.openclaw/tools/sherpa-onnx-tts/runtime`)
中危
File Access
第 67 行
Access to hidden dotfiles in home directory
2. Download a voice model (extracts into `~/.openclaw/tools/sherpa-onnx-tts/models`)
中危
File Access
第 69 行
Access to hidden dotfiles in home directory
Update `~/.openclaw/openclaw.json`:
低危
File Access
第 77 行
Access to hidden dotfiles in home directory
SHERPA_ONNX_RUNTIME_DIR: "~/.openclaw/tools/sherpa-onnx-tts/runtime",
低危
File Access
第 78 行
Access to hidden dotfiles in home directory
SHERPA_ONNX_MODEL_DIR: "~/.openclaw/tools/sherpa-onnx-tts/models/vits-piper-en_US-lessac-high",
缓解建议
Review the upstream repository before copying files into a local skills directory.
Confirm install instructions and supported runtimes against SKILL.md instead of a generic readme.