genmedia-workflow
Warn
Audited by Socket on May 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s capabilities broadly match its stated media-workflow purpose, but it concentrates trust in an external GitHub-hosted CLI that appears to receive both credentials and user media, without enough install/provenance detail in the skill itself. Main concern is supply-chain and credential/data-handling risk, not confirmed malicious intent.
Confidence: 82%Severity: 72%
Audit Metadata