google-veo

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core purpose is coherent, but the skill routes usage through an external platform CLI, requires login to that CLI, uses an official yet weak `curl|sh` install model, and encourages transitive skill installation. This is not clearly malicious, but it carries medium security risk and higher trust requirements than a narrowly scoped direct API integration.

Confidence: 85%Severity: 64%
Audit Metadata
Analyzed At
Mar 18, 2026, 05:53 PM
Package URL
pkg:socket/skills-sh/inference-sh%2Fagent-skills%2Fgoogle-veo%2F@aef03c6df766b825142057eb78e8176838234e38