jianying-editor
Warn
Audited by Socket on Apr 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The editing capabilities are broadly aligned with the stated video-automation purpose, and most package installs appear to be normal developer dependencies. The main concern is install/execution trust: the evidence includes a free-hosted docs site, manual skill loading, unpinned git-clone setup, and especially an opaque shortened `irm ... | iex` installer. No clear credential theft or off-purpose exfiltration is shown, so this is not confirmed malware, but it is a high-risk skill from a supply-chain and agent-trust perspective.
Confidence: 84%Severity: 76%
Audit Metadata