speech-to-text

Warn

Audited by Socket on Jun 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core STT behavior matches its purpose, and data flows appear proportionate to transcription. However, install trust is weakened by a transitive skill-install step for the required CLI, indirect/raw install references, broad Bash permission, and reliance on third-party CLI-mediated auth. This looks more like a medium-risk supply-chain/trust issue than confirmed malware.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 12, 2026, 10:27 PM
Package URL
pkg:socket/skills-sh/qu-skills%2Fskills%2Fspeech-to-text%2F@8f6e4c0055f712dc291afd064cab808c2551adbaf964d726d3630d5b08d08bf5
Security Audit — socket — speech-to-text