ai-marketing-videos
Audited by Socket on Mar 8, 2026
1 alert found:
MalwareThe skill concept aligns with its stated purpose of generating marketing videos via an AI CLI, but it relies on a download-and-execute deployment pattern from unverified external sources (curl | sh and dist.inference.sh) and uses unverifiable binaries. This elevates supply-chain and execution risks. Data flows to external services are plausible but lack explicit privacy/data-handling disclosures. Overall, the footprint is coherent with its marketing-focused purpose but security posture is suspicious due to unverifiable binaries and download-execute patterns; treat as SUSPICIOUS with a high potential risk unless mitigations (verified package registries, signatures, in-repo binaries, clear data-flow/privacy docs) are provided.