motion-graphics

Warn

Audited by Socket on Aug 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s motion-graphics purpose is coherent, but it asks the agent to silently run remote same-org updates and refresh dependent skills before use. The main risks are unpinned `npx` execution, transitive skill installation, and autonomous processing of untrusted external content; there is no clear evidence of credential harvesting or malicious exfiltration.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Aug 21, 2026, 03:23 AM
Package URL
pkg:socket/skills-sh/heygen-com%2Fhyperframes%2Fmotion-graphics%2F@42b7777c377782aa9ef5aeb25c271e97b6fbeaf46e740e5df74b41a68e69bc29
Security Audit — socket — motion-graphics