ai-content-pipeline

Warn

Audited by Socket on Sep 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the media-pipeline capability fits the stated purpose, but the skill’s main footprint is delegated through transitive skill installation and a remotely installed CLI that can receive credentials and upload data. The install path appears officially documented within the same product ecosystem, which lowers malware confidence, but the repeated skill-to-skill installation and credential-bearing external CLI make the overall risk medium-high.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Sep 8, 2026, 05:09 PM
Package URL
pkg:socket/skills-sh/its-a-skill-issue%2Fsuperpowers%2Fai-content-pipeline%2F@ea2be3082656931506e98a7fc215d15196d96ed1141058d84c14bbafb0eaad72
Security Audit — socket — ai-content-pipeline