elevenlabs-tts

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated TTS purpose mostly aligns with the behavior, and the `infsh` installer appears same-org and officially documented, so this is not strong evidence of malware. However, the skill routes requests and credentials through the inference.sh CLI instead of direct ElevenLabs APIs, uses a curl|sh install path, and encourages transitive skill installation, making the overall trust and data-flow footprint broader than a narrowly scoped ElevenLabs TTS skill.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Apr 17, 2026, 09:27 AM
Package URL
pkg:socket/skills-sh/inference-sh-9%2Fskills%2Felevenlabs-tts%2F@4545d3f4faff11a0a7069dcde9cc6b5b76305c73
Security Audit — socket — elevenlabs-tts