ops-voice

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core voice capabilities align with the stated purpose and use official service endpoints, but the setup workflow is overly invasive: it reads raw secrets from multiple local stores, scans all Doppler projects/configs, and validates found keys over the network. Combined with autonomous phone-call capability, this makes the skill higher-risk than a normal voice utility even without clear evidence of malicious exfiltration to attacker-controlled hosts.

Confidence: 91%Severity: 78%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:50 AM
Package URL
pkg:socket/skills-sh/davepoon%2Fbuildwithclaude%2Fops-voice%2F@2290da6b6aad666248809c7703be8df29d720e5d