create-pitch-deck
Warn
Audited by Socket on Aug 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core deck-generation behavior is aligned with the stated purpose, but the telemetry design is inconsistent with the consent claim because remote logging may happen before prompting, and the POST target is an arbitrary config-driven endpoint rather than a fixed official domain. No malware-like payload execution or credential harvesting is shown, but privacy and data-flow controls are weaker than they should be.
Confidence: 85%Severity: 56%
Audit Metadata