openclaw-videotranslate-skill

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The functionality matches a video translation/dubbing skill, and the documented OpenAI endpoints are proportionate, but the trust model is weak: ara.so/Hermes presents a skill whose install instructions fetch and execute code from an unrelated third-party GitHub repo via mutable git clone + local editable pip install, without registry verification, pinning, or checksums. The skill also forwards API credentials to arbitrary configurable endpoints, which is broad but partly consistent with a generic provider design. No confirmed malware or exfiltration is shown, but the install provenance and credential-forwarding flexibility make this high security risk.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Sep 12, 2026, 06:51 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fhermes-skills%2Fopenclaw-videotranslate-skill%2F@07c44e7e9fae7b73cc6c3c373d49affbdcfbb93e38d770eac9ecf869dfebf357
Security Audit — socket — openclaw-videotranslate-skill