oma-slide
Warn
Audited by Socket on Jul 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Suspicious rather than malicious. The skill’s slide-generation and export capabilities fit its stated purpose, and Canva traffic targets an official endpoint, but the required `oma slide` CLI is not verifiable from the skill text and therefore triggers a high supply-chain risk floor. Remote style ingestion plus file-write/tool-exec capability further raises risk, though there is no clear credential harvesting or covert exfiltration behavior.
Confidence: 84%Severity: 74%
Audit Metadata