elevenlabs-tts

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated TTS purpose mostly aligns with the behavior, and the `infsh` installer appears same-org and officially documented, so this is not strong evidence of malware. However, the skill routes requests and credentials through the inference.sh CLI instead of direct ElevenLabs APIs, uses a curl|sh install path, and encourages transitive skill installation, making the overall trust and data-flow footprint broader than a narrowly scoped ElevenLabs TTS skill.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Apr 16, 2026, 12:27 PM
Package URL
pkg:socket/skills-sh/skillsh%2Fskills%2Felevenlabs-tts%2F@4545d3f4faff11a0a7069dcde9cc6b5b76305c73