rendering-generator
Warn
Audited by Socket on Mar 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s file access and rendering workflow broadly match its stated purpose, so it does not look fundamentally malicious. However, the main execution path depends on an unspecified image-generation MCP server, and the skill does not document whether prompts, reference images, and any credentials go directly to official Gemini/Flux endpoints or through a third-party intermediary. That ambiguity makes install/execution trust and data-flow integrity only partially verifiable, raising medium security concern despite otherwise proportionate scope.
Confidence: 81%Severity: 56%
Audit Metadata