qwen-tts
Warn
Audited by Socket on Mar 3, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The code fragment represents a coherent, legitimate self-contained TTS skill intended for local use on Apple Silicon. It exhibits typical supply-chain risk characteristics due to external model downloads (HF mirror) without explicit verification, but there is no evidence of malicious behavior or data exfiltration within the described scope. Recommend tightening model integrity checks (hash/signature verification) and documenting trusted sources to reduce supply-chain risk.
Confidence: 75%Severity: 75%
Audit Metadata