music

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core music-generation behavior is coherent, but the trust model is not: the skill centers on an unverifiable listenhub binary, references auto-install/auto-login, and sits in an ecosystem that uses transitive skill installation. Data flows are broadly proportional to music generation, but the opaque CLI provenance and hidden auth/install path materially raise risk.

Confidence: 86%Severity: 82%
Audit Metadata
Analyzed At
Apr 8, 2026, 01:05 PM
Package URL
pkg:socket/skills-sh/marswaveai%2Fskills%2Fmusic%2F@d9f9bd6e2b267341e8c9561b832c4f50cc0e635c