audio-transcribe

Warn

Audited by Socket on May 2, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core behavior matches its transcription purpose and external LLM use is transparently opt-in, but install trust is weaker than expected because setup depends on a bundled shell script and nonstandard distribution evidence. Scope is mostly proportionate; the main risk is supply-chain trust plus optional external sharing of transcript content during cleanup.

Confidence: 82%Severity: 62%
AnomalyLOW
scripts/setup_env.sh

This Bash fragment is a typical dependency/bootstrapper with no clear indicators of credential theft, obfuscation, exfiltration, or backdoor behavior in the shown code. However, it carries meaningful supply-chain and operational risk: it performs unpinned/rolling pip installs and upgrades without hash/signature verification, uses privileged OS package installation (sudo apt-get) when needed, and—most importantly—executes local companion scripts (patch_clustering.py and setup_mimo.sh) without integrity checks. If those local files or upstream dependencies are tampered with, the installer would run attacker-controlled code with the user’s privileges. Review the contents of the executed companion scripts and consider pinning versions/hashes for reproducibility and risk reduction.

Confidence: 66%Severity: 60%
Audit Metadata
Analyzed At
May 2, 2026, 08:10 PM
Package URL
pkg:socket/skills-sh/zxkane%2Faudio-transcriber%2Faudio-transcribe%2F@4f2ca5d989a0f304e4212b1e74ede371e206a79d