ai-marketing-videos

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill concept aligns with its stated purpose of generating marketing videos via an AI CLI, but it relies on a download-and-execute deployment pattern from unverified external sources (curl | sh and dist.inference.sh) and uses unverifiable binaries. This elevates supply-chain and execution risks. Data flows to external services are plausible but lack explicit privacy/data-handling disclosures. Overall, the footprint is coherent with its marketing-focused purpose but security posture is suspicious due to unverifiable binaries and download-execute patterns; treat as SUSPICIOUS with a high potential risk unless mitigations (verified package registries, signatures, in-repo binaries, clear data-flow/privacy docs) are provided.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Mar 8, 2026, 02:51 AM
Package URL
pkg:socket/skills-sh/1nfsh-s3%2Fskills%2Fai-marketing-videos%2F@0f65afb8bfabf4bd7b74748348c72572336f8b2b