dialogue-audio

Fail

Audited by Socket on Feb 25, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is a documentation/instruction file that relies on a third-party CLI (infsh) and hosted apps (falai/dia-tts). The main security concerns are supply-chain and data-exposure risks: the installer uses a curl|sh pattern (download-and-execute), and user prompts/media are sent to remote services that will process and store them. There are no signs of embedded malware, hardcoded credentials, or obfuscated payloads in the document itself. Risk is primarily from trusting the external domains and the installer/CLI behavior. Recommend users verify installer checksums manually, review where infsh stores tokens, and consider privacy implications of sending prompts and audio to hosted services.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 25, 2026, 05:40 PM
Package URL
pkg:socket/skills-sh/inference-sh-9%2Fskills%2Fdialogue-audio%2F@c0ea42b3110d0539a1376f56536675f799c9a402