woa-cover-image

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill fragment describes a self-contained, local image-generation workflow with clearly bounded data flows and no apparent credential handling or external network leakage. Its purpose-capability alignment is coherent: generate cover images via a local Qwen API using configurable 5D prompts. The only noticeable risk is the exposure of article content to a local endpoint, which is expected for a legitimate image-generation helper, provided the local service is trusted. Overall, the footprint is benign within its stated scope.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 03:24 PM
Package URL
pkg:socket/skills-sh/huozhong-in%2Fnews-aggregator-skill%2Fwoa-cover-image%2F@a63fa61b7f3411512cf31af1e7d0856e35f7ec36