slideshow

Warn

Audited by Socket on Jul 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core slideshow functionality is coherent and mostly benign, but it embeds a silent self-update step that executes an unpinned external CLI command and may refresh additional skills before use. Because the tooling appears to come from the official HyperFrames npm/GitHub ecosystem, this looks more like overreaching auto-update behavior and transitive trust expansion than malware.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Jul 16, 2026, 08:52 AM
Package URL
pkg:socket/skills-sh/heygen-com%2Fhyperframes%2Fslideshow%2F@7b31f30f522435f18a89ab447b6f7f179a6021c44c501ef3d31a513d05ddfb74
Security Audit — socket — slideshow