wjs-voicedrop

Warn

Audited by Socket on Aug 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent with its stated purpose of connecting to a remote VoiceDrop MCP, and there is no evidence of malware-style installers or hidden execution. However, it handles a full-account, non-expiring bearer token, routes it to third-party remote services, warns that it will enter model context/history, and includes an optional cross-domain upload endpoint. This is a legitimate-looking integration with meaningful credential-handling and remote-trust risk, not confirmed malware.

Confidence: 86%Severity: 62%
Audit Metadata
Analyzed At
Aug 21, 2026, 08:57 AM
Package URL
pkg:socket/skills-sh/jianshuo%2Fclaude-skills%2Fwjs-voicedrop%2F@3f41c5d2d72e39318105209c3470b40f0de58423ad79c5c78fa7cd0ad32e32be
Security Audit — socket — wjs-voicedrop