speech-to-text
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core transcription purpose matches the capability, but the skill’s trust model is broader than necessary because it requires a vendor CLI with login, remote job execution, same-org curl|sh-style installation, and transitive skill-install guidance. The behavior is coherent for an inference platform skill, but it carries medium supply-chain and credential-forwarding risk rather than looking outright malicious.
Confidence: 84%Severity: 58%
Audit Metadata