voice-clone
Warn
Audited by Socket on Apr 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is coherent for voice cloning, but it sends sensitive voice samples, text, and API auth to WaveSpeed as a third-party proxy rather than MiniMax's official API. No malware-like installer, hidden execution, or disproportionate credential access is present, so this looks more like a privacy and data-flow trust issue than overtly malicious behavior.
Confidence: 89%Severity: 53%
Audit Metadata