byted-las-long-video-understand

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose and cloud data flow generally match long-video analysis, but its core footprint relies on an unverifiable lasutil CLI plus auto-update/init scripts that receive API credentials. That trust gap is the main issue; this looks more like a high-risk supply-chain/credential-forwarding problem than confirmed malware.

Confidence: 82%Severity: 84%
Audit Metadata
Analyzed At
Apr 21, 2026, 10:41 AM
Package URL
pkg:socket/skills-sh/bytedance%2Fagentkit-samples%2Fbyted-las-long-video-understand%2F@d830e5185df66564a2c13346bbcd71ac700bf6de