text-to-speech

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Overall, the skill’s footprint is partially coherent with its stated purpose, but the install/execution flow (download-and-execute of an unverifiable binary) and ambiguous data-privacy controls introduce notable security risk. The capability to perform TTS with multiple models aligns with the purpose, but the reliance on a remotely downloaded binary and the login credential flow elevate risk to suspicious. Recommend restricting or reworking the install process to use verifiable, signed binaries from an official registry, adding explicit data-privacy disclosures, and clarifying credential handling and data sinks. If these security concerns are not addressed, classify as SUSPICIOUS with elevated risk due to download/executable delivery and potential credential handling.

Confidence: 72%Severity: 65%
Audit Metadata
Analyzed At
Mar 8, 2026, 02:51 AM
Package URL
pkg:socket/skills-sh/1nfsh-s3%2Fskills%2Ftext-to-speech%2F@d3e9fadba36330f6bc3d2001bc9bb594e429b849
Security Audit — socket — text-to-speech