paidf-cosmos-predict

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The workflow purpose and capabilities are mostly aligned for a GPU video-generation skill, and the static command-injection/secret findings are benign documentation artifacts. The main issue is trust: the skill resolves and runs an unverified container image, then forwards HF_TOKEN and optional VLM_API_KEY into it. That credential-forwarding to an unverifiable runtime makes the skill medium-high risk even without confirmed malicious behavior.

Confidence: 89%Severity: 81%
Audit Metadata
Analyzed At
Sep 17, 2026, 02:57 AM
Package URL
pkg:socket/skills-sh/nvidia-tao%2Ftao-skill-bank%2Fpaidf-cosmos-predict%2F@5c64d282f9e962748ede9afbfadeb3a47879c9bca3cd831a831d9f8cc06a2e60
Security Audit — socket — paidf-cosmos-predict