tts-train

Fail

Audited by Socket on Aug 26, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
iterative_train.py

The inspected module itself does not contain explicit malware artifacts (no hardcoded credentials, no network exfiltration calls), so active malicious intent inside this file appears unlikely. However, it provides powerful primitives for arbitrary code execution: unvalidated subprocess invocations (run.sh, training scripts) and an inline python -c built from user-controlled strings. These are genuine command/code injection and supply-chain risks: if an attacker can control CLI arguments or replace expected local scripts/files, they can execute arbitrary code and manipulate model artifacts. Treat this module as moderate-to-high security risk in hostile environments; hardening and sanitization are required before use in multi-tenant or untrusted settings.

Confidence: 90%
Audit Metadata
Analyzed At
Aug 26, 2026, 05:59 PM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Ftts-train%2F@df9d97c4b9f729140d37abe733fa204baf80cd49
Security Audit — socket — tts-train