The skill mostly matches its local TTS purpose, but it exposes unauthenticated network services with filesystem-path access and installs persistent background services.
Review before installing, especially on shared or network-accessible machines. Only proceed if you are comfortable with package installation, model downloads, OpenClaw config edits, user-level autostart services, and local voice-file storage. Bind port 9002 to localhost or firewall it, add authentication, and avoid the direct clone-speak path API until it is restricted to server-managed reference audio IDs.