character-sprite

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s local file access and image-processing steps fit its art-generation purpose, but its core dependency path is under-specified and appears to rely on third-party MCP code that may receive API credentials and user assets. This is not confirmed malware, but install trust and credential-routing are disproportionate enough to warrant caution.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
Sep 19, 2026, 03:59 AM
Package URL
pkg:socket/skills-sh/paulrobello%2Fclaude-office%2Fcharacter-sprite%2F@4667c0ba863bc89291e088761639a68854e52ea22e989b9b58da506f1498c879
Security Audit — socket — character-sprite