speech-to-text

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core functionality matches the stated speech-to-text purpose, and the inference.sh CLI appears to be an official same-org tool with some release verification. However, the skill introduces unnecessary trust expansion through transitive skill installation, a publisher-name mismatch in the install command, and credential/data routing through a third-party CLI platform rather than direct provider APIs. This looks more like a risky platform-wrapper skill than outright malware.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
May 12, 2026, 09:12 PM
Package URL
pkg:socket/skills-sh/inference-sh-9%2Fskills%2Fspeech-to-text%2F@d788fd9e02d93e6a2cd3737d9c8334df9fa8fa7a
Security Audit — socket — speech-to-text