remotion-upgrade

Warn

Audited by Socket on Sep 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core Remotion package-upgrade behavior is coherent and uses official sources, but the added `skills update` step expands scope into third-party transitive skill installation that is not necessary to upgrade project dependencies. No clear malware or credential theft is present, but the trust boundary is broader than the stated purpose.

Confidence: 90%Severity: 62%
Audit Metadata
Analyzed At
Sep 7, 2026, 06:35 PM
Package URL
pkg:socket/skills-sh/remotion-dev%2Fskills%2Fremotion-upgrade%2F@9e3423694f3b1b468510cc3a7afd60d9683bbd4ffffb51ff13e4fa71b7481d4a
Security Audit — socket — remotion-upgrade