selfie

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The selfie skill is largely aligned with its stated purpose: private, owner-scoped selfie generation using a local album and local generation tools, with explicit boundaries against group-wide sharing. The strongest concerns are the NSFW bypass directive and the local server fallback, which could be exploited if chat-context boundaries fail or if the local environment is compromised. Overall security posture is Moderate: low likelihood of remote data leakage, but reasonable concern for local availability, abuse potential in NSFW mode, and process persistence risks. Recommended strengthening includes explicit access-control checks, clarified consent handling for NSFW prompts, and safer server lifecycle management.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:28 PM
Package URL
pkg:socket/skills-sh/ninehills%2Fskills%2Fselfie%2F@5b886509e013dcfa0f3493dc78d2cb2e2a85366e
Security Audit — socket — selfie