qiaomu-info-card-designer

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core card-generation workflow is coherent, and installs appear proportionate, but the skill routes arbitrary URLs through third-party proxy services and processes untrusted remote content with file-writing/rendering capabilities. Main risk is data-flow leakage and prompt-injection exposure rather than confirmed malware.

Confidence: 87%Severity: 59%
Audit Metadata
Analyzed At
Apr 6, 2026, 10:19 AM
Package URL
pkg:socket/skills-sh/joeseesun%2Finfo-card-designer%2Fqiaomu-info-card-designer%2F@f8d6060bd300d96b97d2f83182ec355b7e52729f