mvmaker-h3-skill
Warn
Audited by Socket on Aug 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH-RISK rather than confirmed malware. The stated MV-production purpose matches most file handling and media-processing steps, but the skill’s critical execution path depends on an unverifiable local `minimax-H3-GEN` service that mediates submissions and likely handles RunningHub credentials. That intermediary trust gap is disproportionate enough to make the skill high risk even though there is no direct evidence of deliberate credential theft or overt malicious payloads.
Confidence: 87%Severity: 84%
Audit Metadata