amazon-polly

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent as a Membrane-powered Amazon Polly integration, and the install source is a same-brand npm package rather than an ad-hoc binary. However, it inserts Membrane as a third-party control plane for authentication and API access to AWS Polly, so user data and service credentials flow through an intermediary instead of official AWS-native tooling. This is not confirmed malware, but it creates moderate trust and data-flow risk beyond a direct Polly integration.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 01:00 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Famazon-polly%2F@2af208d173f4c6378d98816ef915b7726c827349
Security Audit — socket — amazon-polly