explainer-video-guide

Fail

Audited by Socket on Feb 25, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This document is a legitimate production guide for generating explainer videos using the infsh CLI and hosted generative apps. The content itself is not malicious, but the recommended installation and usage patterns present supply-chain and data-exfiltration risks: use of curl | sh install, single-domain-hosted checksums, and routine uploading of local media and credentials to remote hosted services. I assess moderate security risk: treat the installer and remote service as untrusted until independently verified, prefer signed/package-managed releases, use least-privilege tokens, and avoid uploading sensitive assets.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 25, 2026, 05:40 PM
Package URL
pkg:socket/skills-sh/inference-sh-9%2Fskills%2Fexplainer-video-guide%2F@c577aa19e5d537fa600defc3ffa816041d862698