Intent-Code Divergence
High
- Confidence
- 99% confidence
- Finding
- The WebSocket client explicitly disables TLS certificate validation by setting check_hostname=False and verify_mode=ssl.CERT_NONE for wss connections. This allows man-in-the-middle attackers to intercept or modify cloned-voice audio, text, res_id values, and API-authenticated traffic despite using WSS, which is especially sensitive in a voice-cloning skill handling biometric and speech data.
