draw
Warn
Audited by Socket on Jul 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's stated purpose is coherent, and its intended network destination appears to be OpenAI, but the real execution path depends on an unverifiable local script that receives API credentials. That hidden code footprint is disproportionate to the transparency provided, so this should be treated as high security risk rather than confirmed malware.
Confidence: 84%Severity: 82%
Audit Metadata