varg-ai

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core media-generation behavior and official varg.ai data flows are coherent with the stated purpose, so this does not look like outright malware. Risk comes from direct credential-file handling, writing secrets into .env, remote version checking plus transitive npx skill updates, and the ability to initiate billing checkout flows using an OTP-derived access token.

Confidence: 83%Severity: 58%
Audit Metadata
Analyzed At
Apr 27, 2026, 03:59 PM
Package URL
pkg:socket/skills-sh/vargHQ%2Fskills%2Fvarg-ai%2F@130a8c4156deabdf9c8aa334fac84eca2e34c363