genmedia-workflow

Warn

Audited by Socket on May 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its stated media-workflow purpose, but it concentrates trust in an external GitHub-hosted CLI that appears to receive both credentials and user media, without enough install/provenance detail in the skill itself. Main concern is supply-chain and credential/data-handling risk, not confirmed malicious intent.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
May 1, 2026, 04:40 PM
Package URL
pkg:socket/skills-sh/fal-ai-community%2Fskills%2Fgenmedia-workflow%2F@6abd7b7cb011a2462281e914ce2fd06a79dda90a