og-image-design

Warn

Audited by Socket on Jun 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core image-generation purpose aligns with the commands and remote services, and the Belt dependency appears to follow official same-brand distribution. The main concerns are transitive skill installation, reliance on an external CLI/service for authenticated operations, mutable raw GitHub install docs, and an example that fetches untrusted search content. This looks more like a legitimate but medium-risk ecosystem-dependent skill than outright malware.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Jun 19, 2026, 02:15 AM
Package URL
pkg:socket/skills-sh/halt-catch-fire%2Fskills%2Fog-image-design%2F@34cf6ee9359743330082d6e9149c4b81a4ebc841316965ba2920bacee464bcde
Security Audit — socket — og-image-design