speech-to-text
Warn
Audited by Socket on May 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core functionality matches the stated speech-to-text purpose, and the inference.sh CLI appears to be an official same-org tool with some release verification. However, the skill introduces unnecessary trust expansion through transitive skill installation, a publisher-name mismatch in the install command, and credential/data routing through a third-party CLI platform rather than direct provider APIs. This looks more like a risky platform-wrapper skill than outright malware.
Confidence: 85%Severity: 58%
Audit Metadata