sora

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill presents a coherent, purpose-aligned workflow for generating/remixing/polling/downloading Sora video assets via a bundled CLI with OpenAI API integration. The required credential (OPENAI_API_KEY) is standard for this kind of tooling, and data flows are primarily between the user, the local agent, the bundled CLI, and OpenAI endpoints. There are no evident unclearly justified outbound data flows, unverifiable binaries, or broad credential exposure. The footprint is proportionate to its stated video-generation purpose, with normal file-system usage for batch processing and asset handling. Overall, the risk profile is low-to-moderate (benign with minor operational data handling considerations).

Confidence: 98%
Audit Metadata
Analyzed At
Mar 8, 2026, 11:02 AM
Package URL
pkg:socket/skills-sh/Rabbit-Ivan%2FIvan-skills%2Fsora%2F@860bbfc8e81f34d0d5e1c09b7ac1ad9ceeeb214a