fal-lip-sync

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's stated purpose is coherent and the fal.ai/GitHub branding appears same-ecosystem, but this entry is mainly a pointer that asks the agent to install an unpinned upstream bundle. The main concern is transitive trust and underspecified install provenance, not confirmed malicious behavior or credential theft.

Confidence: 87%Severity: 52%
Audit Metadata
Analyzed At
May 11, 2026, 11:03 AM
Package URL
pkg:socket/skills-sh/nexu-io%2Fopen-design%2Ffal-lip-sync%2F@312577a6daaa4525288b76584b68cdee40e7dfe1
Security Audit — socket — fal-lip-sync