elevenlabs-tts
Warn
Audited by Socket on Apr 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The stated TTS purpose mostly aligns with the behavior, and the `infsh` installer appears same-org and officially documented, so this is not strong evidence of malware. However, the skill routes requests and credentials through the inference.sh CLI instead of direct ElevenLabs APIs, uses a curl|sh install path, and encourages transitive skill installation, making the overall trust and data-flow footprint broader than a narrowly scoped ElevenLabs TTS skill.
Confidence: 84%Severity: 61%
Audit Metadata