auto-draw-plot
Warn
Audited by Socket on Jul 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's main workflow is coherent for image generation, but it reads local credential files and sends requests through a non-official benszresearch.com/Sub2API gateway rather than the documented OpenAI API. That third-party credential and data routing is disproportionate enough to make the skill high risk even without obvious malware or installer abuse.
Confidence: 89%Severity: 74%
Audit Metadata