speech-to-text

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This Skill is functionally coherent: it documents installing the inference.sh CLI and using it to run hosted Whisper models for transcription. However, it instructs the user to execute a remote install script via curl|sh (download-and-execute) and to run a third-party CLI that will transmit audio and credentials to inference.sh infrastructure. The documentation references transitive skill installation via npx, which increases the attack surface. I assess the package as suspicious from a supply-chain perspective (not confirmed malware): the main risks are download-execute installer, credential forwarding to a third-party service, and transitive installation of additional skills. Users who require strong trust or offline/local-only transcription should avoid the curl|sh install and hosted service calls or verify checksums and host binaries from trusted sources.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 10:43 AM
Package URL
pkg:socket/skills-sh/tul-sh%2Fskills%2Fspeech-to-text%2F@28a2a816ece86deae1ca934acef6944c54e05286