meitu-ai

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s stated purpose and behavior are mostly coherent for a lightweight router, with no clear malicious or unrelated capability. The main risk is trust in the external meitu-cli/delegated tooling: the package appears to come from official PyPI but lacks strong evidence of being published by the same org as Meitu, and credentials may flow through that dependency. This is more a supply-chain and credential-forwarding concern than confirmed malicious behavior.

Confidence: 80%Severity: 57%
Audit Metadata
Analyzed At
Mar 23, 2026, 08:48 AM
Package URL
pkg:socket/skills-sh/tangyang%2Fskills%2Fmeitu-ai%2F@edc85896e8b49dfad4bbb037e39f0c2c4800706c