ai-video-generation

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Overall, the skill presents a coherent purpose with aligned capabilities: it orchestrates the inference.sh CLI to generate videos across numerous models and offers a practical workflow for text-to-video and related tasks. The primary security/risks revolve around dependency on a third-party CLI and cloud backend, which introduces supply-chain and data-handling trust considerations. There are no explicit credential harvesting patterns or dangerous data exfiltration indicators in the described pieces, but the reliance on external services and untrusted input URLs necessitates careful review of the inference.sh data-use policies, provenance of models, and secure supply-chain practices. The footprint is mostly benign given its stated purpose, but the presence of download/install via an external registry and data routing to a third-party service warrants a SUSPICIOUS risk rating pending formal review of trust, provenance, and data handling policies.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 09:55 PM
Package URL
pkg:socket/skills-sh/inferen-sh%2Fskills%2Fai-video-generation%2F@81c173fe8cbfed0a816448b9bdc1b00d0af7c09e