runpod

Warn

Audited by Socket on Mar 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core RunPod API usage is purpose-aligned and routes to official endpoints, but the trust model is weakened by personal-namespace GHCR images, mutable tags, and uploads through unspecified fallback services. This looks more like a legitimate but moderately risky third-party deployment skill than confirmed malware.

Confidence: 83%Severity: 61%
Audit Metadata
Analyzed At
Mar 22, 2026, 05:24 PM
Package URL
pkg:socket/skills-sh/digitalsamba%2Fclaude-code-video-toolkit%2Frunpod%2F@c5d1e5f9bee284b481b3cc20695830bd77121a25