vid-sizzle-reel
Warn
Audited by Socket on May 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose is coherent and it does not request credentials or route data to suspicious endpoints, but it relies on transitive installation of a third-party skill plus unpinned npx execution and a CDN-loaded script. This looks more like a legitimate media-generation workflow with supply-chain and trust-chain risk than malware.
Confidence: 87%Severity: 58%
Audit Metadata