video-tool

Warn

Audited by Socket on May 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core video-processing purpose is plausible, but the skill’s footprint is much broader: it installs third-party code from a personal GitHub repo, asks the agent to handle many credentials, and enables autonomous uploads/public posting. The benign pre-execution checks do not make it malware, but the supply-chain, credential-forwarding, and real-world action scope make this a high-risk skill.

Confidence: 90%Severity: 88%
Audit Metadata
Analyzed At
May 29, 2026, 08:29 AM
Package URL
pkg:socket/skills-sh/alejandro-ao%2Fvideo-tool-cli%2Fvideo-tool%2F@7668bc7b953fbb32c5279eaaca3e5fa6425cf73f
Security Audit — socket — video-tool