video-report

Warn

Audited by Socket on Feb 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

This skill contains insecure and potentially dangerous behavior: it allows arbitrary external content to be written into project source and then executes a local render command that will run that content. That remote-to-execution flow is a common supply-chain/remote-code-execution pattern and should be treated as suspicious. If used as-is, the skill could enable code injection and credential/data exfiltration. Required mitigations: validate and restrict allowed URLs and content types, verify file content before writing, run the render in an isolated sandbox, or provide a safer workflow (store media as a separate asset rather than replacing source code).

Confidence: 80%Severity: 60%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:05 PM
Package URL
pkg:socket/skills-sh/remotion-dev%2Fremotion%2Fvideo-report%2F@8ffdc1995317f9b7f1ed89d262c87fb73a8f992b