SVG Animation Builder
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose is benign, but the practical footprint is mainly remote skill installation through transitive tooling. The official `skills` CLI appears legitimate, yet the installed publisher `agentskillexchange/skills` is not clearly verifiable from the evidence, and the alternate `clawhub` path is also unverified. This is not confirmed malware, but it carries medium-high supply-chain risk disproportionate to a simple SVG animation helper.
Confidence: 85%Severity: 62%
Audit Metadata