sora
Audited by Socket on Mar 8, 2026
1 alert found:
Obfuscated FileThe skill presents a coherent, purpose-aligned workflow for generating/remixing/polling/downloading Sora video assets via a bundled CLI with OpenAI API integration. The required credential (OPENAI_API_KEY) is standard for this kind of tooling, and data flows are primarily between the user, the local agent, the bundled CLI, and OpenAI endpoints. There are no evident unclearly justified outbound data flows, unverifiable binaries, or broad credential exposure. The footprint is proportionate to its stated video-generation purpose, with normal file-system usage for batch processing and asset handling. Overall, the risk profile is low-to-moderate (benign with minor operational data handling considerations).