openclaw-videotranslate-skill
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The functionality matches a video translation/dubbing skill, and the documented OpenAI endpoints are proportionate, but the trust model is weak: ara.so/Hermes presents a skill whose install instructions fetch and execute code from an unrelated third-party GitHub repo via mutable git clone + local editable pip install, without registry verification, pinning, or checksums. The skill also forwards API credentials to arbitrary configurable endpoints, which is broad but partly consistent with a generic provider design. No confirmed malware or exfiltration is shown, but the install provenance and credential-forwarding flexibility make this high security risk.
Confidence: 89%Severity: 78%
Audit Metadata