jianying-recover
Warn
Audited by Socket on Sep 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/VULNERABLE rather than confirmed malware. The skill’s behavior is largely aligned with its recovery purpose and includes strong fail-closed guardrails, but it depends on an externally installed `jianying` CLI whose official provenance is not established by the provided evidence. With no credential collection or obvious exfiltration, the main issue is unverifiable dependency trust, not malicious intent.
Confidence: 82%Severity: 72%
Audit Metadata