mvmaker-h3-skill

Warn

Audited by Socket on Aug 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK rather than confirmed malware. The stated MV-production purpose matches most file handling and media-processing steps, but the skill’s critical execution path depends on an unverifiable local `minimax-H3-GEN` service that mediates submissions and likely handles RunningHub credentials. That intermediary trust gap is disproportionate enough to make the skill high risk even though there is no direct evidence of deliberate credential theft or overt malicious payloads.

Confidence: 87%Severity: 84%
Audit Metadata
Analyzed At
Aug 12, 2026, 08:09 AM
Package URL
pkg:socket/skills-sh/penposs%2Fmvmaker-h3-skills%2Fmvmaker-h3-skill%2F@31381a2c6cdb058bfdd97a518234acea963fdf4f678c7830b09d435bf6b2f52c
Security Audit — socket — mvmaker-h3-skill