This Chinese text-to-speech skill mostly matches its stated purpose, but it ships under-disclosed scripts that can silently modify the installed skill and add hidden audio playback behavior.
Review carefully before installing. The core TTS script does not show credential theft, broad data access, or exfiltration, and VirusTotal/static scan signals are clean. The practical concern is that the package includes undocumented patching scripts and automatic playback behavior. Install only if you are comfortable auditing/removing patch.py and fix.py, and expect generated audio to be played automatically rather than only saved.