oma-slide

Warn

Audited by Socket on Jul 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Suspicious rather than malicious. The skill’s slide-generation and export capabilities fit its stated purpose, and Canva traffic targets an official endpoint, but the required `oma slide` CLI is not verifiable from the skill text and therefore triggers a high supply-chain risk floor. Remote style ingestion plus file-write/tool-exec capability further raises risk, though there is no clear credential harvesting or covert exfiltration behavior.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Jul 28, 2026, 09:48 AM
Package URL
pkg:socket/skills-sh/first-fluke%2Foh-my-agent%2Foma-slide%2F@3253bd0053df4399d1fcd90e4cf8093f41e4224a83689ecd652b66fa7f7b3258
Security Audit — socket — oma-slide