ElevenLabs CLI
PassAudited by ClawScan on Feb 18, 2026.
Overview
The skill's requirements and runtime instructions align with its stated purpose: it only asks for an ElevenLabs API key and describes calling the ElevenLabs API and standard installation methods; nothing in the package suggests unrelated access or suspicious behavior.
This skill appears to do what it says, but it's an unofficial community client — before installing: (1) only provide an ElevenLabs API key (prefer a scoped or expendable key if available); (2) avoid processing highly sensitive audio/text you wouldn't want sent to ElevenLabs; (3) verify the upstream GitHub repo and the Homebrew/Scoop/Docker sources you use (third-party taps/buckets can contain code you should audit); (4) prefer installing/running the CLI in a sandbox/container if you want extra isolation; (5) review ~/.config/elevenlabs-cli/config.toml if you store keys there and remove keys when no longer needed.
