video-clip-extractor

Warn

Audited by Socket on Mar 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The Video Clip Extractor Skill is largely aligned with its stated purpose and presents a coherent workflow for video processing and clip generation. However, the installation pathway relies on downloading and executing code from external, unverifiable sources (astral.sh installer, openclip repo) which introduces supply-chain and credential exposure risks. Because these patterns are present and could lead to unseen payloads or misconfigurations, the overall assessment leans toward SUSPICIOUS rather than Benign. If the external installer and transitive dependencies can be replaced with verifiable, signed packages from official registries and the provenance of dependencies is clearly documented, the risk posture would improve toward Benign.

Confidence: 72%Severity: 62%
Audit Metadata
Analyzed At
Mar 12, 2026, 06:41 AM
Package URL
pkg:socket/skills-sh/linzzzzzz%2Fopenclip%2Fvideo-clip-extractor%2F@55ee28fb0b2a7cf2db853ca3fdbfdf1a30adfe67