jianying-motion

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated editing workflow is internally coherent and comparatively well-scoped, but it depends on an external `jianying` CLI whose provenance could not be verified from official vendor sources or registries. That unverifiable binary requirement creates a mandatory high supply-chain risk even though the skill itself does not show credential theft, covert behavior, or clear exfiltration.

Confidence: 86%Severity: 82%
Audit Metadata
Analyzed At
Sep 19, 2026, 11:56 PM
Package URL
pkg:socket/skills-sh/full-aigc-skills%2Fjianying-skills%2Fjianying-motion%2F@4aa31027edd035953b79e8d385fbcec06f00e2621d94ac3a79bf19531d47d0d1
Security Audit — socket — jianying-motion