Is cyberfront-ai/demo-video safe?
Use with caution. cyberfront-ai/demo-video is not clearly unsafe, but the audit flagged risks to review before you install it. Oathe's behavioral security audit gave the demo-video skill by cyberfront-ai a trust score of 77/100 with 4 findings (2 high).
https://github.com/openclaw/skills/tree/main/skills/cyberfront-ai/demo-video
Is cyberfront-ai/demo-video safe to install?
This skill package appears deceptive or misconfigured, containing no actual skill content and referencing a different skill name in its metadata. While no active malicious behavior was detected, the installation process accessed sensitive credential files.
What security issues were found in cyberfront-ai/demo-video?
Category Scores
Findings (4)
HIGH Empty SKILL.md file -20 ▶
The SKILL.md file contains no content whatsoever, indicating this is not a functional skill package
HIGH Skill name mismatch in lock.json -70 ▶
The lock.json file references 'academic-research-hub' instead of the expected 'cyberfront-ai/demo-video', suggesting deceptive packaging or supply chain confusion
MEDIUM Credential file access during installation -40 ▶
The installation process accessed multiple sensitive credential files including SSH keys, AWS credentials, and environment files
LOW Installation failure -15 ▶
Git clone operation failed due to existing directory, preventing complete installation
Should I install cyberfront-ai/demo-video?
Oathe's verdict for cyberfront-ai/demo-video is CAUTION with a trust score of 77/100. Recommendation: Review before install.