commercial

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities fit commercial media generation, but trust and data-flow integrity are weakened by the unverified `genmedia` naming mismatch and by routing prompts and uploaded media through a third-party gateway instead of direct provider APIs. This looks more like a medium-risk vendor-proxy workflow than confirmed malware.

Confidence: 85%Severity: 62%
Audit Metadata
Analyzed At
May 1, 2026, 09:30 PM
Package URL
pkg:socket/skills-sh/fal-ai-community%2Fskills%2Fcommercial%2F@f11ab5b16995a54ec3b4c9819f3eaab607363dbc