ads-photoshoot
Warn
Audited by Socket on May 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s stated behavior is coherent for product-photo generation, but its core functionality relies on banana-claude, an externally installed personal-repo tool with weak provenance and opaque credential/data handling. Because the skill depends on third-party tooling for API setup and remote generation rather than directly using clearly documented official endpoints, the overall risk is high even though the purpose itself is benign.
Confidence: 85%Severity: 82%
Audit Metadata