speech-to-text

Warn

Audited by Socket on May 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core STT behavior matches its purpose, and data flows appear proportionate to transcription. However, install trust is weakened by a transitive skill-install step for the required CLI, indirect/raw install references, broad Bash permission, and reliance on third-party CLI-mediated auth. This looks more like a medium-risk supply-chain/trust issue than confirmed malware.

Confidence: 85%Severity: 64%
Audit Metadata
Analyzed At
May 19, 2026, 07:52 AM
Package URL
pkg:socket/skills-sh/inference-sh%2Fskills%2Fspeech-to-text%2F@921ccc52a6871f37e4abf0674456c0b5b7ee10d3
Security Audit — socket — speech-to-text