figurine-generator

Warn

Audited by Socket on Aug 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose aligns with image-to-3D generation, but its data flow is not direct: prompts, image references, and the required access key are sent to a third-party gateway rather than official provider endpoints. The CLI/install path is only partially verifiable and unpinned. This looks more like a managed proxy integration than obvious malware, but the credential routing and intermediary architecture create material security and privacy risk.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Aug 28, 2026, 07:06 AM
Package URL
pkg:socket/skills-sh/ai-hub-admin%2Fcraftsman-agent%2Ffigurine-generator%2F@1566b96ad5e3e904981f3a1d2d1b6dc352665a88a29453f5523150fc353034b4
Security Audit — socket — figurine-generator