elevenlabs-tts
Warn
Audited by Socket on Aug 6, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is plausible, but the actual footprint routes use through a third-party CLI/service, asks for login to that intermediary, and encourages transitive skill installation. The mismatch between an ElevenLabs-branded task and inference.sh/Belt-mediated auth and execution raises medium-high supply-chain and credential-forwarding risk.
Confidence: 84%Severity: 78%
Audit Metadata