elevenlabs-tts

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's TTS functionality matches its stated purpose, but it relies on a vendor-controlled external CLI installed via pipe-to-shell, routes requests through inference.sh instead of direct ElevenLabs APIs, forwards authentication to that CLI, grants broad `infsh *` execution, and promotes transitive skill installation. This is not confirmed malware, but the intermediary data flow and trust expansion make the skill medium-to-high risk.

Confidence: 85%Severity: 68%
Audit Metadata
Analyzed At
Apr 14, 2026, 09:11 AM
Package URL
pkg:socket/skills-sh/inference-sh%2Fagent-skills%2Felevenlabs-tts%2F@4545d3f4faff11a0a7069dcde9cc6b5b76305c73