video-lens-gallery

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent and the visible actions are local and proportionate, but the skill depends on and instructs installation of a separate third-party skill from a personal GitHub repo, creating transitive trust and moderate supply-chain risk. No direct credential harvesting or exfiltration is evident in this skill text.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Mar 19, 2026, 04:57 PM
Package URL
pkg:socket/skills-sh/kar2phi%2Fvideo-lens%2Fvideo-lens-gallery%2F@f9d8411904c21a95b00f48de83debd60384ebd6e