google-veo

Fail

Audited by Socket on Mar 27, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The skill’s functional purpose is coherent, but its actual footprint depends on a third-party CLI installed via pipe-to-shell, authenticates through that CLI, and routes Google Veo usage through inference.sh rather than direct official Google endpoints. Same-org hosting and checksum verification reduce concern somewhat, but the combination of remote binary install, credential forwarding, intermediary data flow, and transitive skill installs makes the risk high for an AI agent skill.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
Mar 27, 2026, 02:29 PM
Package URL
pkg:socket/skills-sh/inference-sh-8%2Fskills%2Fgoogle-veo%2F@aef03c6df766b825142057eb78e8176838234e38