train-voice

Warn

Audited by Socket on Aug 26, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
iterative.py

The code has a legitimate purpose as a local voice-model training and evaluation CLI and contains no evident credential theft, network exfiltration, reverse shell, cryptomining, or destructive payload. However, the evaluation path contains a real code-injection vulnerability: command-line evaluation phrases, and potentially path-derived values, are inserted into Python source passed to `python -c` without escaping. An attacker able to supply `--eval-phrases` or control relevant path values could execute arbitrary code with the process privileges. Use structured arguments or safe serialization instead of generated source, and validate persona paths. Malware intent is not demonstrated, but the dynamic execution pattern presents a significant security risk.

Confidence: 98%Severity: 76%
AnomalyLOW
design.py

The code appears to implement an interactive voice-design CLI that generates interview questions, optionally invokes a local interview script, processes responses, and saves JSON output. No clear malware, credential theft, persistence, cryptomining, suspicious network activity, or destructive behavior is present. The main security concerns are path traversal through insufficient persona sanitization for temporary and storage paths, arbitrary output-file writes via the output option, and reliance on an external shell script and imported modules whose implementations are not provided. These issues warrant remediation, but the fragment alone does not establish malicious intent.

Confidence: 96%Severity: 58%
Audit Metadata
Analyzed At
Aug 26, 2026, 06:03 PM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Ftrain-voice%2F@0bcbbb552e67a51ebd13fdca934b43edc98da397b39bd7ad95db291cd2c02f01
Security Audit — socket — train-voice