logo-creator

Warn

Audited by Socket on Jun 17, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/vectorize.py

The code is a straightforward integration utility for an external vectorization API. The main security concerns are the brittle and potentially leaking method of obtaining the API key from ~/.zshrc, and reliance on external network calls which can leak data and depend on external service trust. No explicit malicious behavior detected (no exfiltration beyond intended API usage, no code execution, no hardcoded secrets in source). Risks are moderate due to key retrieval pattern and external dependency.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 17, 2026, 02:09 AM
Package URL
pkg:socket/skills-sh/Hashim1404%2Fagent-skills-and-rules%2Flogo-creator%2F@2b23a5be2e87e4749b436f019db58036a7cec2f7f0eeb73eaa57fa2bd7ed8f10
Security Audit — socket — logo-creator