ai-voice-cloning

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's media-generation behavior largely matches its stated purpose, but it materially expands trust to an external CLI (`belt`) and encourages transitive installation of more skills. Data flows to hosted remote services are expected for TTS, yet the install provenance for the CLI is not established in this file strongly enough to treat it as low risk.

Confidence: 79%Severity: 66%
Audit Metadata
Analyzed At
May 8, 2026, 07:30 PM
Package URL
pkg:socket/skills-sh/skillssh%2Fskills%2Fai-voice-cloning%2F@34bf422268466f47b2b47a2fbce6431aa15ebc9f
Security Audit — socket — ai-voice-cloning