voice-lab
Warn
Audited by Socket on Mar 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s capabilities are largely coherent with a local voice/audio workbench, and there is no clear credential harvesting or exfiltration path. However, the optional `voice-lab[editor]` installation target is not publicly verifiable from the evidence provided, which triggers a high supply-chain risk floor for an unverifiable dependency. Apart from that install trust issue and minor network exposure from `qwen-tts-demo --ip 0.0.0.0`, the footprint is proportionate and mostly local.
Confidence: 84%Severity: 72%
Audit Metadata