figurine-generator
Warn
Audited by Socket on Aug 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose aligns with image-to-3D generation, but its data flow is not direct: prompts, image references, and the required access key are sent to a third-party gateway rather than official provider endpoints. The CLI/install path is only partially verifiable and unpinned. This looks more like a managed proxy integration than obvious malware, but the credential routing and intermediary architecture create material security and privacy risk.
Confidence: 87%Severity: 72%
Audit Metadata