app-icon

Warn

Audited by Socket on Jul 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core icon-editing behavior is coherent and mostly local, but the embedded Gemini install/auth instructions are inconsistent with the official publisher path and route a Google API key into third-party-installed CLI code via api2cli. That supply-chain plus credential-forwarding combination is disproportionate for an app-icon skill.

Confidence: 87%Severity: 84%
Audit Metadata
Analyzed At
Jul 27, 2026, 08:17 AM
Package URL
pkg:socket/skills-sh/melvynx%2Faiblueprint%2Fapp-icon%2F@2fe6da66c59858ee5f3f8e86c9678ed0c5cac8c9ce72843c63ab083ff6f7a86e
Security Audit — socket — app-icon