video-reader
Fail
Audited by Socket on Mar 18, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
SUSPICIOUS. The stated purpose is legitimate, but the skill is built around a mandatory opaque `alma` CLI that uploads user media externally without documented provenance or install trust. Local fallback behavior is proportionate, yet the primary path introduces significant supply-chain and data-flow risk inconsistent with a minimally scoped media-reader skill.
Confidence: 86%Severity: 88%
Audit Metadata