elevenlabs-agents

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
assets/javascript-sdk-boilerplate.js

No strong evidence of intentional malware (no eval/Function, no reverse shells, no file/system manipulation, no obvious exfiltration logic in this module). The dominant security issue is DOM-based XSS: transcript and agent output text is inserted into the page via innerHTML without sanitization, allowing arbitrary script execution if the conversation content can contain HTML/JS. A secondary concern is potential API key exposure if process.env is bundled into a browser artifact; this depends on the build/deployment approach, which is not shown here.

Confidence: 72%Severity: 66%
Audit Metadata
Analyzed At
Sep 15, 2026, 07:27 AM
Package URL
pkg:socket/skills-sh/jezweb%2Fclaude-skills%2Felevenlabs-agents%2F@00fe9e922de5dce33f5e79c49b6a9ea97df42306b4ce60db92aa1f78d8c2d56e
Security Audit — socket — elevenlabs-agents