jianying-transitions

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated video-transition purpose and capabilities are internally coherent, but it depends on an unverifiable external `jianying` CLI that could perform arbitrary actions on local media/projects. The skill text itself is cautious and does not show credential theft or exfiltration behavior, so this is primarily a supply-chain and execution-trust risk rather than confirmed malware.

Confidence: 87%Severity: 76%
Audit Metadata
Analyzed At
Sep 19, 2026, 11:56 PM
Package URL
pkg:socket/skills-sh/full-aigc-skills%2Fjianying-skills%2Fjianying-transitions%2F@456598ca449344d56f988e2724767422d267436cb120ace6f03b4fb497236fb7
Security Audit — socket — jianying-transitions