hub

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Mostly coherent TTS/voice-tooling skill with expected auth, local file use, and API-backed synthesis. The main concerns are delegated trust in the external `voxflow` CLI, installation of third-party recipes/templates, and instructions for the agent to autonomously create GitHub issues; these make the skill better classified as suspicious than fully benign, but there is no strong evidence of malware or credential harvesting from the provided content.

Confidence: 81%Severity: 62%
Audit Metadata
Analyzed At
May 17, 2026, 11:51 PM
Package URL
pkg:socket/skills-sh/VoxFlowStudio%2Fskills%2Fhub%2F@d3402155bd148d0a71733b14cef5230493e54016
Security Audit — socket — hub