video-prompting-guide

Fail

Audited by Socket on Feb 25, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The file is a benign user guide for composing AI video prompts and using a cloud CLI (infsh). It does not contain embedded malware, hard-coded credentials, or obfuscated code. The main security concerns are supply-chain and data-exfiltration risks introduced by recommended workflows: pipe-to-shell installer, downloading binaries from service domains, installing npm packages via npx without pinned hashes, and granting broad allowed-tool permissions that enable arbitrary CLI actions. These are operational risks that can be mitigated with signed artifacts, pinned versions, tighter agent/tool permissions, and clear documentation of data collection.

Confidence: 98%Severity: 90%
Audit Metadata
Analyzed At
Feb 25, 2026, 05:38 PM
Package URL
pkg:socket/skills-sh/inference-sh-9%2Fskills%2Fvideo-prompting-guide%2F@eedfb223be32b19603bdd2f7c5da3c2b7f234a6b