ai-avatar-video

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill’s stated purpose (avatar/talking-head video creation using inference.sh) aligns with its described capabilities and workflows. However, the download-and-execute install pattern (curl ... | sh) and reliance on an unverifiable remote binary introduce meaningful supply-chain risk. Data flow to external media URLs is expected for this domain but warrants input validation/sandboxing. Overall, the footprint is somewhat coherent with the purpose but weighted toward suspicious due to the remote installer pattern and potential third-party binary trust gaps. Treat as SUSPICIOUS with caution and recommend adding verified binary distribution (signed checksums, package registries), explicit origin pinning, and clearer credential/data handling policies.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Mar 8, 2026, 02:51 AM
Package URL
pkg:socket/skills-sh/1nfsh-s3%2Fskills%2Fai-avatar-video%2F@d3217147df847b8a8c4e87817ecc000accf76a15