text-to-speech
Warn
Audited by Socket on Jul 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's TTS purpose is coherent, but its trust model is weak. Main concerns are external CLI dependency, credential forwarding through Belt, inconsistent install provenance cues, wildcard CLI access, and repeated transitive skill installation. I found no clear evidence of outright malware or unrelated credential theft behavior.
Confidence: 86%Severity: 76%
Audit Metadata