jianying-editor

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The editing capabilities are broadly aligned with the stated video-automation purpose, and most package installs appear to be normal developer dependencies. The main concern is install/execution trust: the evidence includes a free-hosted docs site, manual skill loading, unpinned git-clone setup, and especially an opaque shortened `irm ... | iex` installer. No clear credential theft or off-purpose exfiltration is shown, so this is not confirmed malware, but it is a high-risk skill from a supply-chain and agent-trust perspective.

Confidence: 84%Severity: 76%
Audit Metadata
Analyzed At
Apr 4, 2026, 05:32 AM
Package URL
pkg:socket/skills-sh/luoluoluo22%2Fjianying-editor-skill%2Fjianying-editor%2F@e6c4b6e83b787cca8fb8664c6ea87658a23b541f