iflytek-voiceclone-tts

Warn

Audited by Snyk on Jun 18, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The skill makes runtime calls to http://opentrain.xfyousheng.com/voice_train and http://avatar-hci.xfyousheng.com/aiauth/v1/token (for training text, uploads, token auth) and to wss://cn-huabei-1.xf-yun.com/v1/private/voice_clone (for WebSocket TTS), which are invoked during runtime and provide training text/tokens and perform synthesis — i.e., they directly control prompts/instructions and runtime behavior.

Issues (1)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 18, 2026, 03:29 AM
Issues
1
Security Audit — snyk — iflytek-voiceclone-tts