laniameda-gallery-ingest

Warn

Audited by Socket on Jun 19, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
SKILL.md

SUSPICIOUS: the core ingest capability is aligned with the stated purpose, and the required env vars are proportionate, but the skill includes GitHub-based self-update and transitive skill installation instructions from a mutable source, plus a directive to update without asking. This is more a supply-chain and autonomous-update risk than clear malware or credential theft.

Confidence: 79%Severity: 57%
SecurityMEDIUM
scripts/ingest.ts
Audit Metadata
Analyzed At
Jun 19, 2026, 07:31 PM
Package URL
pkg:socket/skills-sh/Michailbul%2Flaniameda-hq%2Flaniameda-gallery-ingest%2F@34bed7b3abb29042a7c7dfa62bdea68ad21436a741c28b5ea981cb6dc3c3b12d
Security Audit — socket — laniameda-gallery-ingest