gen-ai-workflows

Warn

Audited by Socket on Aug 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the workflow scope fits the stated creative purpose and data flows mostly match official Picsart usage, but the required external CLI materially raises trust concerns because reported malicious-package evidence undermines the install path. The skill itself is not overtly malicious, yet using it inherits high supply-chain risk from the gen-ai dependency.

Confidence: 82%Severity: 78%
Audit Metadata
Analyzed At
Aug 28, 2026, 09:31 AM
Package URL
pkg:socket/skills-sh/picsart%2Fgen-ai-cli%2Fgen-ai-workflows%2F@1a7e5960114de3b8168a00be703f7f04c20c111fd639f6f9945b13a30261444e
Security Audit — socket — gen-ai-workflows