suno-engineer

Warn

Audited by Socket on May 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's local file access and prompt-editing behavior fit its stated music-prompt purpose, and there is no clear credential theft or exfiltration path. However, it requires a custom MCP tool with only partial same-publisher evidence and no verifiable public release/install trail in the provided evidence, so the overall security risk remains high under the unverifiable-dependency rule.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
May 14, 2026, 06:30 AM
Package URL
pkg:socket/skills-sh/bitwize-music-studio%2Fclaude-ai-music-skills%2Fsuno-engineer%2F@2462cf036e8602d96b025db708e4f77f807ad60d