gen-ai-workflows
Warn
Audited by Socket on Aug 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the workflow scope fits the stated creative purpose and data flows mostly match official Picsart usage, but the required external CLI materially raises trust concerns because reported malicious-package evidence undermines the install path. The skill itself is not overtly malicious, yet using it inherits high supply-chain risk from the gen-ai dependency.
Confidence: 82%Severity: 78%
Audit Metadata