rtvi-cv-scaffold-vss-service
Warn
Audited by Socket on Aug 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill is purpose-aligned and mostly uses official NVIDIA/VSS components and documented data flows, so it does not look malicious. The main issue is the required customer-supplied parser `.so`, an opaque executable loaded into the service without provenance or verification guidance; combined with host networking and container execution, this makes the skill high security risk despite otherwise coherent behavior.
Confidence: 87%Severity: 72%
Audit Metadata