studioai-generate

Warn

Audited by Socket on May 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s functions fit its stated purpose, and there is no direct malware behavior in the text, but it depends on an unverifiable `studioai-mcp` server that appears to handle Clerk session tokens and mediate all backend calls. That makes the install/execution trust and credential-routing model disproportionately risky relative to the limited transparency provided here.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
May 6, 2026, 12:16 PM
Package URL
pkg:socket/skills-sh/amrtawfik160%2Fstudioai-skills%2Fstudioai-generate%2F@5ab394ee9ddbce7e4872a93a98bb57bc19d9f49d
Security Audit — socket — studioai-generate