social-card-gen

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's stated purpose is coherent, and its requested inputs are mostly proportionate, but the install/execution path is weaker than the description suggests: it runs an unverified npm package via npx and forwards an API key to that external code without showing official package ownership or endpoint details. This looks more like a supply-chain and credential-forwarding risk than confirmed malicious behavior.

Confidence: 80%Severity: 63%
Audit Metadata
Analyzed At
Apr 16, 2026, 05:31 PM
Package URL
pkg:socket/skills-sh/AlekseiUL%2Fsprut-agent-kit%2Fsocial-card-gen%2F@37b1c2f5a1d246c04f18c02bc0aa1cc7cbcaef51
Security Audit — socket — social-card-gen