remotion-upgrade

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core Remotion package-upgrade behavior is coherent and uses normal npm/Remotion tooling, but the fallback path also updates multiple AI skills through an unrelated third-party `skills` CLI with `--yes`. That transitive skill installation is broader than a package-upgrade skill needs and materially increases trust scope, though there is no clear credential theft or malicious exfiltration evidence.

Confidence: 90%Severity: 52%
Audit Metadata
Analyzed At
Sep 19, 2026, 01:48 PM
Package URL
pkg:socket/skills-sh/remotion-dev%2Fclaude-code-plugin%2Fremotion-upgrade%2F@39d20054532ba030e7566792b46b39a74a688c479abd58b75bd918911f906a1e
Security Audit — socket — remotion-upgrade