heygen
Warn
Audited by Socket on Jun 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's broad purpose is coherent, but the actual integration path is a third-party gateway that intermediates HeyGen access and holds the service token server-side. That proxy data flow, combined with local credential storage and unpinned `npx` execution, makes the skill medium/high risk even without confirmed malicious behavior.
Confidence: 84%Severity: 69%
Audit Metadata