studioai-prompt-enhance
Warn
Audited by Socket on May 6, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The core purpose is coherent, but the skill relies on an unverifiable external MCP server and may route prompts, images, and API keys through OpenRouter instead of only official Gemini endpoints. The capability set is mostly aligned with prompt enhancement, yet the undeclared dependency provenance and third-party credential/data routing make the overall skill medium-high risk.
Confidence: 79%Severity: 76%
Audit Metadata