embry-voice-control

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Security
SecurityMEDIUM
src/embry_voice_control/listener_service.py

No direct evidence of malicious behavior or supply-chain malware is present. The code implements an event-journal HTTP API, but the visible routes have no authentication or authorization and expose potentially sensitive journal and audio data while permitting event and consumer-state mutations. These are significant deployment security concerns if the service is reachable by untrusted clients. The fragment also appears syntactically incomplete at the end; review the imported helper modules and deployment controls for integrity, path validation, and access control.

Confidence: 98%Severity: 72%
Audit Metadata
Analyzed At
Aug 26, 2026, 06:03 PM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fembry-voice-control%2F@d6212c86799132e9df26197ecf6965f49543d1fa7c27e270a98dfc213ad1a93c
Security Audit — socket — embry-voice-control