analyze-video

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is internally consistent with its stated purpose: extracting frames with ffmpeg, reading those frames, and editing a prepared visual transcript JSON. There are no network calls, hardcoded secrets, obfuscated payloads, or obvious exfiltration behaviors in the provided fragment. The main security considerations are operational: ensure ffmpeg/ruby commands are run locally from trusted sources, validate and sanitize any file/path inputs to avoid command/path-injection and accidental rm -rf damage, and audit the referenced helper script (prepare_visual_script.rb) before use. Overall, I find the skill benign in intent but with standard local-file-operation risks that require careful implementation and review of the helper script.

Confidence: 85%Severity: 25%
Audit Metadata
Analyzed At
Feb 16, 2026, 12:57 AM
Package URL
pkg:socket/skills-sh/barefootford%2Fbuttercut%2Fanalyze-video%2F@1f698ea88e2032b5469378019280f11061d78152