creative-media

Warn

Audited by Socket on Aug 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose matches the capability of a hosted creative-media runtime, but the skill relies on unpinned remote `npx` execution and explicit transitive skill installation. Data flows to Luxin-hosted infrastructure are coherent with the purpose, yet persistent hosted outputs and remote retention increase privacy risk. Main concern is install/upgrade trust rather than clear malicious behavior.

Confidence: 82%Severity: 66%
Audit Metadata
Analyzed At
Aug 16, 2026, 12:23 AM
Package URL
pkg:socket/skills-sh/danielgwilson%2Fluxin%2Fcreative-media%2F@53dcdcc92291730d4532f9b513e900ac46e18d938823e07d32dbcef435f27b42
Security Audit — socket — creative-media