wjs-voicedrop
Warn
Audited by Socket on Aug 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is mostly coherent with its stated purpose of connecting to a remote VoiceDrop MCP, and there is no evidence of malware-style installers or hidden execution. However, it handles a full-account, non-expiring bearer token, routes it to third-party remote services, warns that it will enter model context/history, and includes an optional cross-domain upload endpoint. This is a legitimate-looking integration with meaningful credential-handling and remote-trust risk, not confirmed malware.
Confidence: 86%Severity: 62%
Audit Metadata