videodb-skills

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

This SKILL.md describes a high-capability video skill that requires installing third-party code via npx and pip and supplying an API key. The manifest itself does not contain code or explicit malicious payloads, but the operational footprint is high-risk: transitive installs, implicit download-and-execute setup, credential forwarding to an external service, and real-time screen/audio capture. These capabilities are plausible for the stated purpose (video upload, transcription, capture, and generation), but they are sensitive and should be treated as potentially dangerous without additional transparency: explicit network endpoints, least-privilege guidance for API keys, user-confirmation requirements for capture/upload, and a verifiable provenance/lockfile for the SDK and skill code. Recommend manual review of the video-db SDK source, inspection of post-install scripts, verification of the service endpoints, and restricting capture permissions and API keys to the minimum necessary before use.

Confidence: 75%Severity: 65%
Audit Metadata
Analyzed At
Mar 3, 2026, 04:43 AM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fvideodb-skills%2F@87b0826077556c11d25f4f59d3432a08aefb03b6