faster-whisper

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This is documentation for a local transcription skill (faster-whisper) that legitimately requires downloading ML model weights and installing PyTorch/ffmpeg. I found no indicators of deliberate credential harvesting, data exfiltration, obfuscated payloads, or embedded malware in the provided text. The primary security concerns are standard supply-chain risks: automatic model and wheel downloads, and setup scripts that perform automated installs (especially on Windows via winget). These behaviors are expected for ML tooling but increase attack surface if upstream repositories, wheel indices, or the setup scripts themselves are compromised. Recommend: (1) inspect the actual setup.sh / setup.ps1 scripts before running — ensure they do not execute unverified remote code or pipe-to-shell; (2) pin model and wheel checksums or verify signatures where possible; (3) run installs in isolated environments (VMs/containers) and avoid running scripts with elevated privileges without review. Overall: low likelihood of intentional malicious behavior in the provided documentation, but moderate supply-chain risk due to external binary downloads and auto-install behavior.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 28, 2026, 09:09 PM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Ffaster-whisper%2F@2cdd24fa3ad52a128cde5aef575fd3aba3e3ddfe