text-to-speech

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s stated purpose matches its TTS capabilities and the inference.sh branding appears internally consistent, but it relies on an external CLI/service, requires login credentials, and encourages transitive installation of additional skills. Risk is medium from supply-chain trust and credential forwarding rather than clear malicious behavior.

Confidence: 80%Severity: 58%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:30 PM
Package URL
pkg:socket/skills-sh/inference-sh%2Fagent-skills-registry%2Ftext-to-speech%2F@45d7a73fbdfd55f3a24ca1f09e0e23082c24720b