slides-grab-design
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core slide-generation purpose is plausible, but the skill expands into credential-backed image generation using ~/.codex/auth.json and an unsupported private backend, plus remote content ingestion via web search/yt-dlp. Those data flows and credential handling are not well-aligned with a narrowly scoped design skill.
Confidence: 84%Severity: 76%
Audit Metadata