elevenlabs-tts
What this skill does
Generate ElevenLabs text-to-speech audio using local voice profiles and environment variables for configuration.
github/mengto - Data Exfiltration - 4.6k stars
Threat analysis
Skill info
pkg:github/MengTo/Skills@4a0d3b4?skill=elevenlabs-ttsAssessments (2)
Data Exfiltration
Data Exfiltration via local-llm-review
scripts/generate_voice.py
The script uses `urlopen` to make requests to the ElevenLabs API (`https://api.elevenlabs.io`). While this is expected behavior for a TTS service, the script does not explicitly validate or sanitize iConfiguration Management
Configuration Management via local-llm-review
scripts/generate_voice.py
The script reads from `.env` files and environment variables, but does not enforce strict access controls or validation on the values read, which could lead to misconfiguration or exposure of sensitivBadge
Add the Anomity scan badge for elevenlabs-tts to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of elevenlabs-tts? Report an issue or request a rescan.




