logo-generator

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is mostly aligned with its design-generation purpose and uses normal local scripts plus standard Python packages, but it has a meaningful medium risk because it explicitly supports custom GEMINI_API_BASE_URL routing. If used with official Google endpoints, it appears benign; if configured to a third-party endpoint, prompts, images, and API keys are exposed to an intermediary. Overall classification: SUSPICIOUS due to data-flow flexibility and unverifiable dependency scope, not confirmed malware.

Confidence: 89%Severity: 57%
Audit Metadata
Analyzed At
Apr 16, 2026, 05:17 PM
Package URL
pkg:socket/skills-sh/op7418%2Flogo-generator-skill%2Flogo-generator%2F@bf4e9ac4d4428bda261afcfe981871ceb92d94e6