suno-engineer
Warn
Audited by Socket on May 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's local file access and prompt-editing behavior fit its stated music-prompt purpose, and there is no clear credential theft or exfiltration path. However, it requires a custom MCP tool with only partial same-publisher evidence and no verifiable public release/install trail in the provided evidence, so the overall security risk remains high under the unverifiable-dependency rule.
Confidence: 84%Severity: 72%
Audit Metadata