slides

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s purpose and actions mostly align, and its data flows point to ListenHub-owned services rather than obvious exfiltration endpoints. However, the required listenhub CLI is the core trust anchor and is not verifiably installed or pinned in this skill, while the workflow also implies credential use and remote content processing. Main risk is supply-chain and credential exposure through an insufficiently verifiable external binary, not confirmed malware.

Confidence: 81%Severity: 82%
Audit Metadata
Analyzed At
Apr 8, 2026, 01:05 PM
Package URL
pkg:socket/skills-sh/marswaveai%2Fskills%2Fslides%2F@327bcbf2df5c60326f62a66f28e75b71b2a56089