text-to-speech

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill's purpose and behavior mostly align with text-to-speech, and no clear malicious or off-purpose data exfiltration is shown. However, its core functionality depends on an unverified local `telclaude` CLI that likely receives the OpenAI API key, with no trustworthy install/provenance details in the skill; that makes the execution and credential path higher risk than a direct official API integration.

Confidence: 81%Severity: 74%
Audit Metadata
Analyzed At
Apr 9, 2026, 12:04 PM
Package URL
pkg:socket/skills-sh/avivsinai%2Ftelclaude%2Ftext-to-speech%2F@6b40f8f96e02a1df50616cf29dab841e36284d4e