gen-ai-use

Warn

Audited by Socket on Aug 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's functionality is coherent with its stated Picsart media-generation purpose, and data flows mostly target official Picsart services. However, the recommended curl|bash installer and especially the documented npm path to a package with a public malicious-package compromise record create high install-trust and credential-forwarding risk.

Confidence: 85%Severity: 82%
Audit Metadata
Analyzed At
Aug 28, 2026, 09:31 AM
Package URL
pkg:socket/skills-sh/picsart%2Fgen-ai-cli%2Fgen-ai-use%2F@1a88f0ef7931cc0b7a15a3846427a1bd19d6690ad70772d4718ea2a2b687e380
Security Audit — socket — gen-ai-use