install-civitai-videoflow-bundle

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The installer provides a coherent, multi-step process to install and validate the Civitai Videoflow bundle with dependency-safe sequencing and environment checks. Key security considerations include secure handling of credentials, integrity verification for externally fetched packages, and careful logging to prevent secret leakage. The SSH-first approach with HTTPS fallback and lack of explicit pinning or hash verification for dependencies are the primary risk areas. Improving by adding mandatory integrity checks (pinned versions, checksums, or package signing), explicit secret handling policies (masked logs, ephemeral storage, least-privilege access), and conceding a non-optional CIVITAI_ACCOUNT field or clear guidance on its necessity would strengthen security posture.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 27, 2026, 03:22 PM
Package URL
pkg:socket/skills-sh/feed-mob%2Fagent-skills%2Finstall-civitai-videoflow-bundle%2F@548241ec0de08f77981e859034b52510cd0d2c6c