commercial
Warn
Audited by Socket on May 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s capabilities fit commercial media generation, but trust and data-flow integrity are weakened by the unverified `genmedia` naming mismatch and by routing prompts and uploaded media through a third-party gateway instead of direct provider APIs. This looks more like a medium-risk vendor-proxy workflow than confirmed malware.
Confidence: 85%Severity: 62%
Audit Metadata