text-to-speech
Warn
Audited by Socket on Apr 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill's purpose and behavior mostly align with text-to-speech, and no clear malicious or off-purpose data exfiltration is shown. However, its core functionality depends on an unverified local `telclaude` CLI that likely receives the OpenAI API key, with no trustworthy install/provenance details in the skill; that makes the execution and credential path higher risk than a direct official API integration.
Confidence: 81%Severity: 74%
Audit Metadata