paidf-cosmos-predict
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The workflow purpose and capabilities are mostly aligned for a GPU video-generation skill, and the static command-injection/secret findings are benign documentation artifacts. The main issue is trust: the skill resolves and runs an unverified container image, then forwards HF_TOKEN and optional VLM_API_KEY into it. That credential-forwarding to an unverifiable runtime makes the skill medium-high risk even without confirmed malicious behavior.
Confidence: 89%Severity: 81%
Audit Metadata