elevenlabs-dialogue
Warn
Audited by Socket on May 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core purpose is plausible, and sending dialogue text to inference.sh is consistent with hosted TTS generation, but the install path is not internally clean. Requiring transitive installation of `belt-sh/cli` from a different publisher identity than `inference-sh`, plus raw install docs and broad Bash access, makes the skill higher risk than its narrow stated purpose warrants.
Confidence: 87%Severity: 76%
Audit Metadata