ai-marketing-videos
Warn
Audited by Socket on Apr 25, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core capability fits the stated purpose, but the trust model is heavy: pipe-to-shell installation of a vendor CLI, credential submission to that CLI, wildcard Bash allowance, and transitive installation of more skills. This looks like a coherent product-integration skill rather than confirmed malware, but it carries meaningful supply-chain and credential-forwarding risk.
Confidence: 84%Severity: 76%
Audit Metadata