elevenlabs-tts

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's TTS functionality matches its stated purpose, but it relies on a vendor-controlled external CLI installed via pipe-to-shell, routes requests through inference.sh instead of direct ElevenLabs APIs, forwards authentication to that CLI, grants broad `infsh *` execution, and promotes transitive skill installation. This is not confirmed malware, but the intermediary data flow and trust expansion make the skill medium-to-high risk.

Confidence: 85%Severity: 68%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:47 PM
Package URL
pkg:socket/skills-sh/inferen-sh%2Fskills%2Felevenlabs-tts%2F@b8f5aba7814cb81358af38c927f9b63b23667d83