openai-whisper
Fail
Audited by Socket on Mar 9, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The skill is coherently scoped for local transcription using Whisper. It relies on an official package manager (Homebrew) for installation and performs local processing with transient, expectation-consistent model downloads into a user-specific cache. Data flows are appropriate for the stated purpose, with minimal surface area for credential exposure or external data exfiltration. Overall risk is low to moderate due to the initial model download step, but it remains within expected behavior for a local, offline-capable transcription tool.
Confidence: 98%
Audit Metadata