tts-horus
Audited by Socket on Mar 17, 2026
1 alert found:
Obfuscated FileThis module is not obviously embedded malware itself, but it contains several supply-chain and local-execution risks that could be abused: (1) importing triggers an automatic pip install which performs network downloads and code execution, and (2) it executes a local adapter script (batch.py) from user-writable paths with user text passed on the command line, enabling arbitrary code execution and data exfiltration if that adapter is malicious. The snippet also appears incomplete (missing PROMPT value and truncated main invocation). Recommend: disable or remove auto-install behavior, avoid passing sensitive text on the command line (use stdin or temp files with strict permissions), require explicit configuration for adapter paths, and add integrity/allowlist checks (signatures or hashes) before executing any local adapters. Do not run this in sensitive environments until adapters and install behavior are audited.