app-icon
Warn
Audited by Socket on Jul 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core icon-editing behavior is coherent and mostly local, but the embedded Gemini install/auth instructions are inconsistent with the official publisher path and route a Google API key into third-party-installed CLI code via api2cli. That supply-chain plus credential-forwarding combination is disproportionate for an app-icon skill.
Confidence: 87%Severity: 84%
Audit Metadata