sherpa-onnx-tts

Warn

Audited by Socket on Mar 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill enables a legitimate local TTS workflow using sherpa-onnx offline assets. The core concern is the download-and-extract of unverifiable binaries from GitHub without explicit verification (signatures/checksums). This creates a non-trivial supply-chain risk and warrants elevated security caution (securityRisk at least 0.7). Otherwise, the data flows are confined to local machine inputs and outputs with no credential handling or external exfiltration detected. Recommend adding explicit integrity checks (signatures/checksums, pinned hashes) and repository-verifiable provenance for the binaries before lowering risk.

Confidence: 98%Severity: 80%
Audit Metadata
Analyzed At
Mar 9, 2026, 09:13 PM
Package URL
pkg:socket/skills-sh/ComposioHQ%2Fopenclaw-composio%2Fsherpa-onnx-tts%2F@777f60a17b0c11fc17a3740c8ec830117d25e255