image-to-video

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill is SUSPICIOUS: it claims a safe, guided workflow for image-to-video generation but relies on downloading and executing an external binary from an unverified source, with potential data exfiltration risk via prompts/images to a remote service. While some safeguards (checksum verification) exist, the overall pattern (download-execute from a non-official registry) and data-flow paths warrant caution and possible rework to use officially verifiable package registries or self-contained local tooling. If the binary’s provenance and data-handling practices are auditable and clearly documented, risk could be reduced; absent that, treat as suspicious.

Confidence: 68%Severity: 62%
Audit Metadata
Analyzed At
Mar 8, 2026, 02:51 AM
Package URL
pkg:socket/skills-sh/1nfsh-s3%2Fskills%2Fimage-to-video%2F@bb2b40493f06da1c8e5aa2f298e45fa0ef5002f6