promo-video
Audited by Socket on Sep 15, 2026
2 alerts found:
Anomalyx2The skill is mostly coherent with its stated promo-video purpose: it builds Remotion projects, reads local project context, and sends TTS requests to ElevenLabs. The main risks are supply-chain and trust expansion: unpinned installs, explicit installation of other skills, and forwarding an API key to a remote service. No clear malicious or covert exfiltration behavior is present, but the transitive skill installation and credential-handling make it suspicious rather than fully benign.
The supplied fragment is a setup guide, not malware code. It contains meaningful supply-chain and operational risks: direct execution of a remote shell script, unpinned third-party skill installation, handling of an ElevenLabs secret, and especially the destructive `rm -rf ~/.git` recommendation. Review and pin external sources, inspect skill code before execution, protect the `.env` file, and remove or replace the deletion command. No direct evidence of intentional malware is present in the provided text.