text-to-music
Warn
Audited by Socket on May 9, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's function is coherent, but it routes prompts, optional images, and bearer-authenticated requests through a Rebyte proxy instead of official Google endpoints, and it reads local auth material via a helper/file pair not fully verifiable from the skill itself. This looks more like a legitimate third-party integration than malware, but the proxy-based credential and data flow creates medium security risk.
Confidence: 84%Severity: 59%
Audit Metadata