voice-changer

Warn

Audited by Socket on Feb 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] [Documentation context] Installation of third-party script detected BENIGN overall with standard ML-model supply-chain considerations. No evidence of malicious behavior or data exfiltration in the fragment; ensure integrity of locally stored models and pinned dependencies when deploying. LLM verification: [LLM Escalated] The voice-changer skill implements local, expected operations for RVC-based voice conversion and does not show explicit malicious code in the provided files. The primary security concern is supply-chain and integrity: unverified model downloads (pan.quark.cn) and bundled environment/model binaries increase risk of tampered or malicious artifacts. Execution of local scripts via predictable paths and bundled native libraries amplifies impact if the repository or host filesystem is compromised. Rec

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 22, 2026, 12:30 PM
Package URL
pkg:socket/skills-sh/wlzh%2Fskills%2Fvoice-changer%2F@af2ebb01a441509663563394a45da9f5479948ae