slides-grab-design

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core slide-generation purpose is plausible, but the skill expands into credential-backed image generation using ~/.codex/auth.json and an unsupported private backend, plus remote content ingestion via web search/yt-dlp. Those data flows and credential handling are not well-aligned with a narrowly scoped design skill.

Confidence: 84%Severity: 76%
Audit Metadata
Analyzed At
Apr 29, 2026, 12:03 PM
Package URL
pkg:socket/skills-sh/NomaDamas%2Fslides-grab%2Fslides-grab-design%2F@fd9c8fdd41f6e427a7eb01b0c256193032509b7a
Security Audit — socket — slides-grab-design