vhscli

Warn

Audited by Socket on Aug 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities mostly match its stated media-analysis/generation purpose, and the install path uses the official npm registry, but it requires executing an unpinned `@latest` package on each run and routes user data through VHS-managed backend services instead of direct provider APIs. This looks more like a high-trust thin-client integration than outright malware, but the mutable install path and centralized third-party data flow raise meaningful security risk.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Aug 11, 2026, 12:48 PM
Package URL
pkg:socket/skills-sh/getvhs%2Fvhscli-skills%2Fvhscli%2F@8be83bf2fc83216e6b6e7afd5f2554946eb4de9f
Security Audit — socket — vhscli