meeting-to-video

Fail

Audited by Socket on Mar 25, 2026

2 alerts found:

AnomalyObfuscated File
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose and capabilities mostly align for local Remotion video generation, and the TTS credential scope is proportionate. Main concerns are transitive skill installation, unshown shell scripts, and npx-based execution across multiple agent environments; these raise supply-chain and trust-chain risk without clear evidence of malicious intent.

Confidence: 80%Severity: 62%
Obfuscated FileHIGH
scripts/setup.sh

The code is a standard project setup script with no explicit malicious behavior. It relies on external package ecosystems (npm/npx) which introduces supply-chain risk if remote packages are compromised, but the script itself does not implement malicious payloads. Recommend validating the source of dependencies, using lockfiles, and considering offline installation or audit of any remotely fetched skills to mitigate risk.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 25, 2026, 03:16 PM
Package URL
pkg:socket/skills-sh/53able%2Fskills%2Fmeeting-to-video%2F@cb4ea88fbacd77fd19fb3bae903f403b20cff8ab
Security Audit — socket — meeting-to-video