davinci-resolve

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core Resolve scripting examples are coherent and locally scoped, but the optional MCP integration introduces an unverified local server and arbitrary script execution capability without provenance details. No direct credential theft or external exfiltration is evident, so this is not confirmed malware, but the MCP portion raises meaningful security risk.

Confidence: 84%Severity: 57%
Audit Metadata
Analyzed At
Mar 18, 2026, 07:15 AM
Package URL
pkg:socket/skills-sh/phuetz%2Fcode-buddy%2Fdavinci-resolve%2F@44f167489d17de405ec4aed6efb2a939558154d5