speak-webhooks-events
Warn
Audited by Socket on Apr 4, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is not overtly malicious and its direct API call goes to a plausible official Speak endpoint, but the core SDK dependency is not publicly verified and the instructions do not actually implement webhook/event handling as claimed. The main risk is unclear dependency provenance combined with credential forwarding into that SDK, plus broader-than-necessary agent permissions.
Confidence: 84%Severity: 58%
Audit Metadata