qwen-tts

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The code fragment represents a coherent, legitimate self-contained TTS skill intended for local use on Apple Silicon. It exhibits typical supply-chain risk characteristics due to external model downloads (HF mirror) without explicit verification, but there is no evidence of malicious behavior or data exfiltration within the described scope. Recommend tightening model integrity checks (hash/signature verification) and documenting trusted sources to reduce supply-chain risk.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 3, 2026, 04:07 PM
Package URL
pkg:socket/skills-sh/stvlynn%2Fskills%2Fqwen-tts%2F@3b8c6b65db91e95e9f7c6819f3c6e7048becc218