laniameda-gallery-ingest
Warn
Audited by Socket on Jun 19, 2026
2 alerts found:
AnomalySecurityAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core ingest capability is aligned with the stated purpose, and the required env vars are proportionate, but the skill includes GitHub-based self-update and transitive skill installation instructions from a mutable source, plus a directive to update without asking. This is more a supply-chain and autonomous-update risk than clear malware or credential theft.
Confidence: 79%Severity: 57%
Securityscripts/ingest.ts
MEDIUMSecurityMEDIUM
scripts/ingest.ts
Audit Metadata