face-swap
Warn
Audited by Socket on May 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is internally coherent for RunComfy-based face swapping and uses same-org, documented install and API paths, so it does not look like credential harvesting malware. However, it is a high-sensitivity dual-use deepfake skill, includes transitive skill installation, and relies on external media plus a CLI install/download chain, making the overall security posture medium risk rather than benign.
Confidence: 86%Severity: 52%
Audit Metadata