remotion-upgrade
Warn
Audited by Socket on Sep 7, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core Remotion package-upgrade behavior is coherent and uses official sources, but the added `skills update` step expands scope into third-party transitive skill installation that is not necessary to upgrade project dependencies. No clear malware or credential theft is present, but the trust boundary is broader than the stated purpose.
Confidence: 90%Severity: 62%
Audit Metadata