google-veo

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core function is coherent, but the skill depends on a same-org remote-installed CLI, sends Veo requests through inference.sh instead of direct Google APIs, uses relatively broad `belt *` permissions, and encourages transitive skill installation. This looks more like a hosted platform wrapper than a direct Google Veo integration; risky but not confirmed malicious.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
May 2, 2026, 04:30 PM
Package URL
pkg:socket/skills-sh/infsh-skills%2Fskills%2Fgoogle-veo%2F@3bfbc94c5dff40820f6ed6b9c5d2aaf240539ff2
Security Audit — socket — google-veo