voice-clone

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is coherent for voice cloning, but it sends sensitive voice samples, text, and API auth to WaveSpeed as a third-party proxy rather than MiniMax's official API. No malware-like installer, hidden execution, or disproportionate credential access is present, so this looks more like a privacy and data-flow trust issue than overtly malicious behavior.

Confidence: 89%Severity: 53%
Audit Metadata
Analyzed At
Apr 18, 2026, 01:13 AM
Package URL
pkg:socket/skills-sh/wulaosiji%2Fskills%2Fvoice-clone%2F@0106904726f9a470b6fa0909bcc076b78c9123ef