capcut-edit
Warn
Audited by Socket on Sep 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s capabilities broadly match its stated purpose of local CapCut/JianYing draft editing, and most data flows are proportionate. The main concern is install/execution trust: the workflow depends on an unofficial third-party `capcut-cli` with no official CapCut/ByteDance provenance and no pinning or verification shown in the skill. Optional OpenAI transcription is coherent and not inherently suspicious. Overall this looks like a legitimate but higher-risk third-party workflow integration rather than confirmed malware.
Confidence: 86%Severity: 72%
Audit Metadata