ai-voice-cloning
Audited by Socket on Mar 7, 2026
1 alert found:
Obfuscated FileThe skill's footprint is largely aligned with its stated purpose: it enables AI voice generation using multiple models and supports workflows for long-form content, video, and podcast contexts. There are reasonable supply-chain concerns due to transitive tool installations and reliance on external CLIs (infsh, media-merger, bytedance tool) that require trust in registries and provenance. No explicit credential harvesting or exfiltration patterns are evident in the described usage. Overall risk is present due to third-party tooling and install flows, but the capability set remains proportionate to the described voice-generation use case. Treat as SUSPICIOUS for elevated risk due to dependency/install-chain risks; otherwise BENIGN if provenance and registry trust are verified.