elevenlabs-stt

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core function is plausible, but the skill's real footprint is broader and less direct than advertised. It routes ElevenLabs-related tasks through a third-party CLI/service, grants wildcard `infsh` shell access, and promotes transitive skill installation. This is not confirmed malware, but the install trust, intermediary data flow, and permission scope are disproportionate enough to warrant caution.

Confidence: 83%Severity: 72%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:48 PM
Package URL
pkg:socket/skills-sh/inferen-sh%2Fskills%2Felevenlabs-stt%2F@4ab5e18fc3ef2898fe9e720ce13048824b783267