text-to-music

Warn

Audited by Socket on May 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's function is coherent, but it routes prompts, optional images, and bearer-authenticated requests through a Rebyte proxy instead of official Google endpoints, and it reads local auth material via a helper/file pair not fully verifiable from the skill itself. This looks more like a legitimate third-party integration than malware, but the proxy-based credential and data flow creates medium security risk.

Confidence: 84%Severity: 59%
Audit Metadata
Analyzed At
May 9, 2026, 05:06 AM
Package URL
pkg:socket/skills-sh/rebyteai%2Frebyte-skills%2Ftext-to-music%2F@8804f87fba0a9843def51b224110adb670d2ff29