google-veo

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's basic function is coherent, but it relies on a third-party platform/CLI that intermediates both authentication and Google Veo requests, and it encourages transitive skill installation. Same-org evidence for inference.sh lowers pure supply-chain concern, yet the proxy-style data flow and credential forwarding make the overall risk medium.

Confidence: 82%Severity: 66%
Audit Metadata
Analyzed At
Apr 9, 2026, 08:04 AM
Package URL
pkg:socket/skills-sh/tool-belt%2Fskills%2Fgoogle-veo%2F@aef03c6df766b825142057eb78e8176838234e38