text-to-speech

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s core behavior matches its text-to-speech purpose and its tool scope is narrow, but it relies on a non-registry external CLI installed via pipe-to-shell and promotes transitive installation of other skills. There is no clear evidence of malicious intent or off-purpose credential theft, but the supply-chain trust model is materially riskier than a normal documentation-only skill.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 14, 2026, 09:13 AM
Package URL
pkg:socket/skills-sh/inference-sh%2Fagent-skills%2Ftext-to-speech%2F@a408017171b96a1070ea7c7af2505e600fa9627a