elevenlabs-storyteller

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The package appears to implement a legitimate TTS utility using ElevenLabs, but documentation/instructions embed an automated outbound flow that directs generated audio files to a specific DingTalk group via a special file tag. This behavior is disproportionate to the stated purpose and poses a real privacy/data-exfiltration risk if users process sensitive files. Treat the presence of a hardcoded external recipient and explicit 'direct send' instruction as suspicious: require explicit opt-in, remove or parameterize the group target, and surface upload authentication and consent before use.

Confidence: 75%Severity: 65%
Audit Metadata
Analyzed At
Feb 16, 2026, 01:03 PM
Package URL
pkg:socket/skills-sh/liuhetian%2Fsimple-skills%2Felevenlabs-storyteller%2F@d10141813f224fe0d10fe2e91afb69524cb75606