layered-img

Warn

Audited by Socket on Jun 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities are mostly coherent with its stated image-layering purpose and it does not request credentials or route data through obvious attacker infrastructure. The main concern is install trust: optional PPT export relies on unpinned npm dependencies whose publisher/provenance was not verified from the provided evidence, so the skill carries medium supply-chain risk rather than clear malicious intent.

Confidence: 83%Severity: 52%
Audit Metadata
Analyzed At
Jun 4, 2026, 12:23 PM
Package URL
pkg:socket/skills-sh/artifact-kit%2Flayered-img-skill%2Flayered-img%2F@c2af1aef1013ba12e10d37e37415473074bdce1b
Security Audit — socket — layered-img