vhscli

Warn

Audited by Socket on May 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's media-analysis and generation behavior is broadly aligned with its stated purpose, but the trust model is weak. It mandates unpinned npx execution of a remote CLI, routes local files and prompts to server-side backends, and provides limited provenance or endpoint verification. This looks more like a high-trust third-party integration than overt malware, but the install and data-flow risks are non-trivial.

Confidence: 80%Severity: 63%
Audit Metadata
Analyzed At
May 14, 2026, 03:02 PM
Package URL
pkg:socket/skills-sh/getvhs%2Fvhscli-skills%2Fvhscli%2F@e50f37c41af90e793f1d6fc830cda97c2d4e3f47