speechace

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's overall purpose is coherent and the CLI install source is legitimate, but it routes Speechace authentication and API traffic through Membrane's own platform rather than directly to Speechace. This third-party credential handling and proxying is broader than a simple Speechace integration and creates meaningful security/privacy risk despite not looking overtly malicious.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 09:15 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fspeechace%2F@4814ca6cd42ed5b0f782fe30b4fa2b1d92c875da
Security Audit — socket — speechace