product-sheet-generate
Warn
Audited by Socket on Mar 26, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is coherent for a product-sheet image skill, but the main execution path relies on an unverifiable local CLI wrapper that uploads files and returns download URLs without documented provenance or official endpoint mapping. The capability fits the purpose, yet install/execution trust and data-flow transparency are insufficient.
Confidence: 86%Severity: 82%
Audit Metadata