mux-video

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is documentation and examples for integrating with Mux Video and handling webhooks in an Inngest pipeline. The capabilities described align with the stated purpose: required credentials are appropriate (Mux API tokens and webhook signing secret), network calls target official Mux APIs for asset and upload management, and webhook handling to a custom endpoint is normal for integrations. The main operational risks are: (1) webhook payloads (including passthrough and metadata) are sent to a non-Mux domain — verify and trust that host; (2) examples use long-lived API credentials via Basic auth — protect and scope these credentials in production; and (3) permissive CORS example ("*") may be too broad. There is no evidence of obfuscation, download-and-execute supply-chain tricks, credential harvesting to unknown domains, or embedded malicious code in this document. Overall the content appears BENIGN functional integration guidance with moderate operational considerations around trusting the webhook endpoint and protecting API secrets.

Confidence: 85%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 06:46 PM
Package URL
pkg:socket/skills-sh/joelhooks%2Fjoelclaw%2Fmux-video%2F@a6e7701e9245ce66c4b20846f5ac8e944514aa0c