text-to-speech

Warn

Audited by Socket on Jun 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is mostly coherent with its stated TTS purpose, but it carries medium risk because it requires installing external skills/CLI tooling, uses a registry-mediated trust chain, and routes requests through the inference.sh platform rather than direct vendor APIs. This looks more like a platform wrapper than malware, but the transitive installation pattern and installer trust questions make it suspicious rather than fully benign.

Confidence: 83%Severity: 58%
Audit Metadata
Analyzed At
Jun 19, 2026, 02:15 AM
Package URL
pkg:socket/skills-sh/halt-catch-fire%2Fskills%2Ftext-to-speech%2F@d55717725a67d1dce88119f7c26e9efbbd18c95a91c4c358ee58bad44245411a
Security Audit — socket — text-to-speech