capcut-edit

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its stated purpose of local CapCut/JianYing draft editing, and most data flows are proportionate. The main concern is install/execution trust: the workflow depends on an unofficial third-party `capcut-cli` with no official CapCut/ByteDance provenance and no pinning or verification shown in the skill. Optional OpenAI transcription is coherent and not inherently suspicious. Overall this looks like a legitimate but higher-risk third-party workflow integration rather than confirmed malware.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Sep 18, 2026, 01:41 PM
Package URL
pkg:socket/skills-sh/renezander030%2Fcapcut-cli%2Fcapcut-edit%2F@68cb2807e1127fe6d8b35a52f06ac95590b3f4934cea695578abe7151815f47c
Security Audit — socket — capcut-edit