remotion-upgrade
Warn
Audited by Socket on Sep 19, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core Remotion package-upgrade behavior is coherent and uses normal npm/Remotion tooling, but the fallback path also updates multiple AI skills through an unrelated third-party `skills` CLI with `--yes`. That transitive skill installation is broader than a package-upgrade skill needs and materially increases trust scope, though there is no clear credential theft or malicious exfiltration evidence.
Confidence: 90%Severity: 52%
Audit Metadata