jianying-harness

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated purpose and behavior are mostly coherent, and it includes strong safety constraints, but it critically relies on an external `jianying` CLI whose provenance is not clearly verifiable from official same-org sources. No direct exfiltration, installer chain, or overtly malicious behavior appears in the skill content, yet the unverifiable external binary dependency keeps overall risk high.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
Sep 19, 2026, 11:56 PM
Package URL
pkg:socket/skills-sh/full-aigc-skills%2Fjianying-skills%2Fjianying-harness%2F@57e7b70ebb531e1a700f104f0c6fffdda64e950f2d2240543303f4d33183ff0e
Security Audit — socket — jianying-harness