google-veo

Warn

Audited by Socket on Jul 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but it depends on a third-party intermediary CLI/platform, forwards user auth through that CLI, and instructs transitive skill installation. Install sources appear same-org and documented, which lowers malware concern, but the indirect data flow and expanded trust chain make this higher risk than a simple vendor API skill.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Jul 22, 2026, 07:33 AM
Package URL
pkg:socket/skills-sh/halt-catch-fire%2Fskills%2Fgoogle-veo%2F@c8e989dc89f254340ffa1b9749a927f83ee5e31d6f2ba1ef1f5ca57df79db1dd
Security Audit — socket — google-veo