jianying-motion
Warn
Audited by Socket on Sep 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s stated editing workflow is internally coherent and comparatively well-scoped, but it depends on an external `jianying` CLI whose provenance could not be verified from official vendor sources or registries. That unverifiable binary requirement creates a mandatory high supply-chain risk even though the skill itself does not show credential theft, covert behavior, or clear exfiltration.
Confidence: 86%Severity: 82%
Audit Metadata