text-to-speech
Audited by Socket on Mar 8, 2026
1 alert found:
MalwareOverall, the skill’s footprint is partially coherent with its stated purpose, but the install/execution flow (download-and-execute of an unverifiable binary) and ambiguous data-privacy controls introduce notable security risk. The capability to perform TTS with multiple models aligns with the purpose, but the reliance on a remotely downloaded binary and the login credential flow elevate risk to suspicious. Recommend restricting or reworking the install process to use verifiable, signed binaries from an official registry, adding explicit data-privacy disclosures, and clarifying credential handling and data sinks. If these security concerns are not addressed, classify as SUSPICIOUS with elevated risk due to download/executable delivery and potential credential handling.