album-art-director

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The core skill behavior is coherent and mostly local, but it depends on an externally allowed MCP tool whose provenance and data handling are not verifiable from the provided evidence. No direct credential theft or malicious routing is shown, yet the unverifiable tool creates a significant supply-chain trust risk disproportionate to an otherwise simple documentation/prompting skill.

Confidence: 79%Severity: 72%
Audit Metadata
Analyzed At
Mar 27, 2026, 11:27 PM
Package URL
pkg:socket/skills-sh/bitwize-music-studio%2Fclaude-ai-music-skills%2Falbum-art-director%2F@8f44ba1178ea367a36307ff1bd065ca601592317