voicemode-connect

Warn

Audited by Socket on Jul 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and data flow are mostly coherent with remote voice routing through voicemode.dev, but it depends on an unpinned third-party npm bridge that handles OAuth/session material. This is a real supply-chain and credential-forwarding risk, though not strong evidence of malware or unrelated exfiltration.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
Jul 29, 2026, 03:26 AM
Package URL
pkg:socket/skills-sh/mbailey%2Fvoice-mcp%2Fvoicemode-connect%2F@b66285ec07effe3d8f8b5cef1c69b4333535af2ee86b53f06b4c905d4daa0743
Security Audit — socket — voicemode-connect