creative-review

Warn

Audited by Socket on Jun 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core capabilities fit a creative-review skill, and ffmpeg/yt-dlp usage is proportionate to frame extraction and comparison. The main concern is install trust: the documented npm package for agent-browser appears inconsistent with official upstream ownership/docs, and the multi-skill dependency chain broadens trust. No clear credential harvesting, secret-file access, exfiltration endpoint, or malicious payload execution is present in the provided skill.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 16, 2026, 11:37 PM
Package URL
pkg:socket/skills-sh/broomva%2Fskills%2Fcreative-review%2F@3268d8459259f6a114ca22384e6f2ebca3cc3bf12a06ed0949a8915351189a4a
Security Audit — socket — creative-review