elevenlabs-voice-changer
Warn
Audited by Socket on Aug 6, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated voice-changing purpose matches the capability, but the trust model is broader than necessary: it requires a transitive skill install plus a separately installed/login-gated CLI that intermediates audio and credentials through inference.sh infrastructure. This is not confirmed malware, but it is a medium-high supply-chain and credential-forwarding risk for a narrowly scoped media task.
Confidence: 84%Severity: 73%
Audit Metadata