visual-artifact

Warn

Audited by Socket on Jul 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose and data flows are broadly coherent for artifact rendering and optional Cloudflare publishing, but it depends on an unverifiable compiled CLI and allows that CLI to receive Cloudflare credentials. That combination makes the skill high risk despite no clear evidence of intentional malware or off-purpose exfiltration.

Confidence: 86%Severity: 82%
Audit Metadata
Analyzed At
Jul 28, 2026, 10:55 PM
Package URL
pkg:socket/skills-sh/iurysza%2Fvisual-artifact-renderer%2Fvisual-artifact%2F@0f473c53286cbbca84a9e15509eae5f378c4ea14bfd975a4beb17724b01eb587
Security Audit — socket — visual-artifact