video-reader

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The stated purpose is legitimate, but the skill is built around a mandatory opaque `alma` CLI that uploads user media externally without documented provenance or install trust. Local fallback behavior is proportionate, yet the primary path introduces significant supply-chain and data-flow risk inconsistent with a minimally scoped media-reader skill.

Confidence: 86%Severity: 88%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:44 PM
Package URL
pkg:socket/skills-sh/ninehills%2Fskills%2Fvideo-reader%2F@5d9616610885d71f28980d3f0f4413a7fe51ff41