elevenlabs-stt
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core function is plausible, but the skill's real footprint is broader and less direct than advertised. It routes ElevenLabs-related tasks through a third-party CLI/service, grants wildcard `infsh` shell access, and promotes transitive skill installation. This is not confirmed malware, but the install trust, intermediary data flow, and permission scope are disproportionate enough to warrant caution.
Confidence: 83%Severity: 72%
Audit Metadata