ai-typography
Warn
Audited by Socket on Apr 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated typography purpose is plausible, but the skill's core capability is mostly a wrapper around an unverified third-party nano-banana-pro dependency with weak provenance and likely credential/API mediation. The local specimen generation is benign, but the external generator introduces disproportionate supply-chain and credential-flow risk.
Confidence: 84%Severity: 82%
Audit Metadata