ai-video-generation

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The AI video generation workflow is functionally coherent but carries notable supply-chain and data-flow risks primarily due to the curl | sh install pattern, remote binary distribution, and potential for unreviewed transitive dependencies. Although there is a checksum step, the reliance on remote installers and execution without in-repo provenance remains a concern. Recommendation: replace remote installer with pinned, in-repo verified packages or signed artifacts, enforce strict data-handling disclosures, and limit credential exposure during login. Treat as SUSPICIOUS to HIGH-RISK pending mitigations.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 11:15 AM
Package URL
pkg:socket/skills-sh/tul-sh%2Fskills%2Fai-video-generation%2F@e073beb52fcec771c32dbd987bd00dd505638b12