world-class-carousel
Warn
Audited by Socket on Mar 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core rendering and content-generation behavior matches the stated purpose, but the skill expands into persistent self-modifying memory and routes prompts/assets plus an API key through a third-party AI gateway rather than an official model endpoint. This is not confirmed malware, but it has meaningful credential-forwarding and external data-flow risk beyond a simple local carousel generator.
Confidence: 84%Severity: 64%
Audit Metadata