spark-video-episode
Warn
Audited by Socket on Jun 16, 2026
2 alerts found:
AnomalySecurityAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s capabilities largely match its stated video-production purpose and its user-approval gates are a strong mitigating control, so this is not confirmed malware. The main concern is the mandatory self-update via unverified git pull from whatever remote the local clone already trusts, plus broad execution of local scripts and unclear provenance of the model wrapper.
Confidence: 100%Severity: 60%
Securityreferences/spark-video-cast/SKILL.md
MEDIUMSecurityMEDIUM
references/spark-video-cast/SKILL.md
Audit Metadata