elevenlabs-dialogue
Warn
Audited by Socket on Jul 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose is coherent, but its trust chain is not: the core install instruction names a different org (`belt-sh/cli`) than the documented official publisher (`inference-sh`). Because the skill requires an external CLI login and routes prompts through that CLI, the publisher mismatch and transitive installation pattern materially increase risk even without direct evidence of malware.
Confidence: 87%Severity: 74%
Audit Metadata