video-ingest

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This SKILL.md documents a local Inngest-based video ingest pipeline and provides operator commands to send events, monitor runs, and troubleshoot worker health. I found no signs of obfuscated code, hardcoded secrets, remote download-and-execute chains, or external exfiltration endpoints. The main risks are operational: the pipeline automates powerful actions (downloading and storing videos, transcribing, writing Vault notes), and the README includes admin commands that control local services. If the local worker or Inngest endpoints were compromised or accidentally exposed, event payloads (which may contain URLs or transcript content) and generated artifacts on NAS/Vault could be exfiltrated. Overall this document appears coherent and consistent with its stated purpose; security risk is primarily around the powerful automation and local admin commands rather than explicit malicious behavior in the skill file itself.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 02:01 AM
Package URL
pkg:socket/skills-sh/joelhooks%2Fjoelclaw%2Fvideo-ingest%2F@c141105e49c45fbd3d871fbc19fdc6dcee4d81e8