studioai-generate
Warn
Audited by Socket on May 6, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s functions fit its stated purpose, and there is no direct malware behavior in the text, but it depends on an unverifiable `studioai-mcp` server that appears to handle Clerk session tokens and mediate all backend calls. That makes the install/execution trust and credential-routing model disproportionately risky relative to the limited transparency provided here.
Confidence: 84%Severity: 82%
Audit Metadata