finish-talking-head
Warn
Audited by Socket on Jul 24, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The workflow purpose and capabilities are broadly coherent for a video-finishing skill, but the core trust boundary is a locally installed `chengfeng-videocut` plugin/runtime whose scripts are executed directly without publicly verifiable provenance. That makes this high supply-chain risk rather than confirmed malware; no explicit credential theft, exfiltration endpoint, or deceptive behavior is visible in the skill text.
Confidence: 84%Severity: 79%
Audit Metadata