veo3-1

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The provided README describes a legitimate-sounding CLI skill to generate short videos through a third-party API (grsai.com). No explicit malicious code is present in the fragment, but there are meaningful supply-chain and data-exposure concerns: (1) recommending a curl|sh installer from astral.sh is a high-risk pattern that can lead to arbitrary code execution if the remote script or distribution is compromised, and (2) use of a third-party gateway for Veo 3.1 means prompts and API keys are exposed to that operator and must be trusted. Before using this skill, review the actual implementation (scripts/generate_video.py) for logging of secrets, endpoint addresses, TLS handling, and filename sanitization; and avoid executing remote install scripts without verification (prefer pinned checksums, signature verification, or package manager installs).

Confidence: 98%Severity: 90%
Audit Metadata
Analyzed At
Feb 28, 2026, 07:59 AM
Package URL
pkg:socket/skills-sh/delneg%2Fnano-banana-pro-skill-grsai-com%2Fveo3-1%2F@a06e42079b2d998fbce321e223491f2052f4f700