happy-horse-audio-reference-to-video

Warn

Audited by Socket on Aug 12, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s overall purpose fits media generation, but its trust and data-flow story is inconsistent. Uploading reference media and using an API key are proportionate, yet the claimed Happy Horse integration appears to route through differently branded infrastructure with mismatched auth conventions, so endpoint ownership and credential destination are not clearly verifiable from the skill text.

Confidence: 80%Severity: 62%
SecurityMEDIUM
resources/config.example.json

No malicious code behavior is demonstrated in this fragment because it contains only static configuration. However, it embeds a plaintext API key and an external service base URL, creating a significant credential-leak and unauthorized-access risk if used by surrounding code or if the secret is reused elsewhere. Additional context (how this config is loaded and how requests are made) is required to assess whether the external calls are legitimate and whether the key is scoped/rotated appropriately.

Confidence: 70%Severity: 70%
Audit Metadata
Analyzed At
Aug 12, 2026, 12:19 PM
Package URL
pkg:socket/skills-sh/wubin1836%2Fai-hive-agent-skills%2Fhappy-horse-audio-reference-to-video%2F@0eccc79cea549f2b4e8127157c5be01da86c5949136843ea97c36fd5a399a01b
Security Audit — socket — happy-horse-audio-reference-to-video