elevenlabs-agents

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This repository/documentation is a legitimate-sounding SDK and agent builder for ElevenLabs. There are no obvious backdoors, obfuscated payloads, or calls to suspicious external domains in the supplied content. The primary security considerations are operational: (1) ensure the server-side API key remains only on the server and the server endpoint returns only short-lived signed URLs, (2) audit any server-side code that uses child_process to ensure user input is never passed to shells unsafely, (3) validate and authorize client tool inputs (e.g., the navigate tool) to prevent malicious redirects, (4) protect sensitive documents in knowledge bases from unintended disclosure, and (5) treat global CLI installs and third-party scripts as supply-chain risk and pin/verify packages. Overall, this appears benign but with typical moderate operational risks that require secure implementation.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 1, 2026, 10:40 PM
Package URL
pkg:socket/skills-sh/jezweb%2Fclaude-skills%2Felevenlabs-agents%2F@a855f40c8eb438b8cb5e41f0ba2ad487b3cebd21