google-veo

Warn

Audited by Socket on Aug 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The stated purpose is coherent, but the skill’s footprint depends on transitive installation of third-party skills/CLI and routes prompts plus authentication through inference.sh/belt instead of official Google interfaces. Main concerns are supply-chain trust, credential forwarding to external tooling, and repeated skill-to-skill installation instructions rather than overt malware.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Aug 6, 2026, 05:03 AM
Package URL
pkg:socket/skills-sh/whytryharder%2Fskills%2Fgoogle-veo%2F@d0540cae80007be31844827b9b9b36a814f07a3a435f73f2e394eb4c09a976ee
Security Audit — socket — google-veo