generate-brand-assets
Warn
Audited by Socket on Jul 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is coherent, but the execution path is inconsistent with the claim of requiring no extra dependencies and relies on an unverified npx package name. No credential theft or exfiltration is evident, but the supply-chain risk is high enough to avoid classifying this as benign.
Confidence: 90%Severity: 72%
Audit Metadata