figure-composer

Warn

Audited by Socket on Jul 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core figure-composition purpose is coherent, and there is no clear credential theft or exfiltration behavior, but the skill relies on unpinned transitive skill loads and delegates untrusted vision-derived content through sub-agents in a write/exec-capable workflow. Risk is medium due to trust-chain and indirect prompt-injection exposure rather than confirmed malware.

Confidence: 81%Severity: 52%
Audit Metadata
Analyzed At
Jul 2, 2026, 01:21 AM
Package URL
pkg:socket/skills-sh/JimLiu%2Fscience-skills%2Ffigure-composer%2F@c2c6460cc6228b357f1b9de1ccb95bef273c8e4a4c3e323ba1fa582bc6ac0568
Security Audit — socket — figure-composer