ai-marketing-videos

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill itself is coherent with its stated purpose (AI marketing video generation) and does not contain direct malicious code in the provided text. However, it relies on high-risk supply-chain patterns: a curl|sh installer, transitive npx skill installs, and forwarding of authentication to hosted inference services. These patterns create realistic credential-forwarding and supply-chain compromise risks. Recommend treating this skill as moderately high risk until installers and transitive packages are audited and users are instructed to verify checksums and avoid running unverified pipe-to-shell commands. Avoid running the default curl|sh pipeline and review any npx-installed skills before use.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 12:33 PM
Package URL
pkg:socket/skills-sh/tul-sh%2Fskills%2Fai-marketing-videos%2F@f4d06a62f44ef086de46ac6a3b18cdd01dfd817a