chat-with-anyone

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/voice_design.py

The code appears to be a legitimate Noiz voice-design API client and shows no clear malware behavior. The main security issues are trust in the user-supplied --base-url, which can redirect API-key and image uploads to an arbitrary host, and unsanitized server-controlled voice_id used in output paths, which can permit path traversal or unintended file writes. Restrict or validate the base URL, sanitize voice_id to a safe filename component, and apply response size/content validation.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 17, 2026, 05:32 AM
Package URL
pkg:socket/skills-sh/noizai%2Fskills%2Fchat-with-anyone%2F@004dca061409b8523f62e4b9d6212d6b117c1106a9dc73ab89f3a368c2905089
Security Audit — socket — chat-with-anyone