speech-to-text

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core transcription purpose matches the capability, but the skill’s trust model is broader than necessary because it requires a vendor CLI with login, remote job execution, same-org curl|sh-style installation, and transitive skill-install guidance. The behavior is coherent for an inference platform skill, but it carries medium supply-chain and credential-forwarding risk rather than looking outright malicious.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 18, 2026, 09:13 PM
Package URL
pkg:socket/skills-sh/inference-sh-9%2Fskills%2Fspeech-to-text%2F@8a91e250ce34d99bf00a81e86be3f4a0b1276b54