podcast-generation

Fail

Audited by Socket on Apr 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The stated purpose and required credentials are broadly coherent for a podcast/TTS skill, and the intended service appears to be official Volcengine TTS. However, the skill’s main behavior is delegated to an opaque local Python script that the agent is explicitly told not to inspect, so actual credential routing, endpoints, and dependency trust cannot be verified from the skill text alone. This is not fundamentally incompatible with the purpose, but it creates medium security risk due to hidden execution and credential forwarding to unreviewed local code.

Confidence: 80%Severity: 52%
Audit Metadata
Analyzed At
Apr 28, 2026, 01:27 AM
Package URL
pkg:socket/skills-sh/stophobia%2Fdeerflow2.0-enhanced%2Fpodcast-generation%2F@536a21e0e2e22044f3deb2f839a6179ab17092b9
Security Audit — socket — podcast-generation