tts-horus

Fail

Audited by Socket on Mar 17, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
taxonomy/taxonomy.py

This module is not obviously embedded malware itself, but it contains several supply-chain and local-execution risks that could be abused: (1) importing triggers an automatic pip install which performs network downloads and code execution, and (2) it executes a local adapter script (batch.py) from user-writable paths with user text passed on the command line, enabling arbitrary code execution and data exfiltration if that adapter is malicious. The snippet also appears incomplete (missing PROMPT value and truncated main invocation). Recommend: disable or remove auto-install behavior, avoid passing sensitive text on the command line (use stdin or temp files with strict permissions), require explicit configuration for adapter paths, and add integrity/allowlist checks (signatures or hashes) before executing any local adapters. Do not run this in sensitive environments until adapters and install behavior are audited.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 17, 2026, 06:41 AM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Ftts-horus%2F@7aaa69a90db24e1af3d44112b525b9e8609de87d
Security Audit — socket — tts-horus