remotion-best-practices

Warn

Audited by Socket on Sep 24, 2026

1 alert found:

Anomaly
AnomalyLOW
remotion-upgrade/REFERENCE.md

SUSPICIOUS: The core Remotion upgrade steps are coherent and use official Remotion/npm sources, so the main package-upgrade behavior looks benign. The notable risk is the transitive `npx skills update ... --yes` step, which expands trust to multiple additional skills and executes fetched code without separate verification; that makes the skill higher risk than a normal dependency-upgrade helper.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Sep 24, 2026, 05:42 AM
Package URL
pkg:socket/skills-sh/openai%2Fplugins%2Fremotion-best-practices%2F@96b155644f75fc7fcb3141515df6ab11af9a7b1088e930fee8e366aba38bb588
Security Audit — socket — remotion-best-practices