synthesize

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core behavior matches text-to-speech, but it depends on a nonstandard local Kokoro wrapper installed via another skill rather than a clearly official upstream CLI. No clear exfiltration or credential abuse is present, so this looks like a moderate supply-chain and transitive-trust risk, not confirmed malware.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 4, 2026, 09:55 AM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fsynthesize%2F@2dce5649c276213ed3f17ed12642720f547923bf