draw

Warn

Audited by Socket on Jul 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's stated purpose is coherent, and its intended network destination appears to be OpenAI, but the real execution path depends on an unverifiable local script that receives API credentials. That hidden code footprint is disproportionate to the transparency provided, so this should be treated as high security risk rather than confirmed malware.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
Jul 28, 2026, 05:14 AM
Package URL
pkg:socket/skills-sh/mathruffian-dot%2F2026-YouTube%2Fdraw%2F@043900926452ed60a082e3f9bf3f097be45bf05b132bbb5f2f1c31943aff6c57
Security Audit — socket — draw