ai-voice-cloning

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is largely aligned with its stated purpose: it enables AI voice generation using multiple models and supports workflows for long-form content, video, and podcast contexts. There are reasonable supply-chain concerns due to transitive tool installations and reliance on external CLIs (infsh, media-merger, bytedance tool) that require trust in registries and provenance. No explicit credential harvesting or exfiltration patterns are evident in the described usage. Overall risk is present due to third-party tooling and install flows, but the capability set remains proportionate to the described voice-generation use case. Treat as SUSPICIOUS for elevated risk due to dependency/install-chain risks; otherwise BENIGN if provenance and registry trust are verified.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 12:12 PM
Package URL
pkg:socket/skills-sh/toolshell%2Fskills%2Fai-voice-cloning%2F@ef3523801f66313d94d3c763063123903dbe213e