videoagent-audio-studio

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated audio-generation purpose is plausible, and the requested credentials match the task, but the default data flow is misaligned: credentials and user content are routed through a third-party hosted proxy instead of directly to official APIs. The repo-local server script and unpinned proxy install add supply-chain risk, and the vendor workflow mismatch reduces trust.

Confidence: 90%Severity: 80%
AnomalyLOW
proxy/api/stats.js

This code appears to implement a usage-statistics endpoint and dashboard, with no clear malicious or supply-chain behavior. The primary security concerns are fail-open authentication when STATS_KEY is unset, possible credential exposure through query parameters, and potential XSS if usage-store data contains attacker-controlled action names or dates. The severity depends on how the usage data is populated and how the endpoint is deployed.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 15, 2026, 01:13 AM
Package URL
pkg:socket/skills-sh/pexoai%2Fpexo-skills%2Fvideoagent-audio-studio%2F@6c36818a6f42039ff0f27567a0c1c8dfc65ad2df8f7d09e97567afa5dfb85481
Security Audit — socket — videoagent-audio-studio