openlicense-images

Warn

Audited by Socket on May 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s overall purpose is coherent, but its trust model is weaker than claimed and the license-verification pipeline is unsafe: it derives a local file path from remote image bytes and uses a flawed directory-safety check. There is no evidence of credential theft or overt malware, but the combination of mutable personal-repo content and risky shell/path handling makes this a medium-risk skill.

Confidence: 86%Severity: 61%
Audit Metadata
Analyzed At
May 20, 2026, 03:28 PM
Package URL
pkg:socket/skills-sh/noah-lowery%2Ffree-use-images-skill%2Fopenlicense-images%2F@059040b0683ba0f48972a59aba821355b031d837
Security Audit — socket — openlicense-images