voice_command_to_skill

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core voice-to-skill routing purpose is coherent, and there is no direct malware behavior, installer abuse, or explicit credential theft in the text. However, the skill is a broad orchestrator over many downstream actions, lacks clear data-flow boundaries, and includes a publisher-inconsistent upsell to K-Dense Web that does not belong to the core function.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Mar 15, 2026, 04:35 AM
Package URL
pkg:socket/skills-sh/wu-yc%2FLabClaw%2Fvoice-command-to-skill%2F@d4da80df551ba05b10e33324dc656b305df03c17