chat-with-anyone
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
AnomalyAnomalyscripts/voice_design.py
LOWAnomalyLOW
scripts/voice_design.py
The code appears to be a legitimate Noiz voice-design API client and shows no clear malware behavior. The main security issues are trust in the user-supplied --base-url, which can redirect API-key and image uploads to an arbitrary host, and unsanitized server-controlled voice_id used in output paths, which can permit path traversal or unintended file writes. Restrict or validate the base URL, sanitize voice_id to a safe filename component, and apply response size/content validation.
Confidence: 97%Severity: 58%
Audit Metadata