google-veo

Warn

Audited by Socket on May 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core function is coherent, but the skill depends on a same-org remote-installed CLI, sends Veo requests through inference.sh instead of direct Google APIs, uses relatively broad `belt *` permissions, and encourages transitive skill installation. This looks more like a hosted platform wrapper than a direct Google Veo integration; risky but not confirmed malicious.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
May 13, 2026, 03:34 AM
Package URL
pkg:socket/skills-sh/inference-sh%2Fskills%2Fgoogle-veo%2F@acec751bfae2e7a045abb15e3d2a61e921c29cc9