@1365/stickerforge
Warn
Audited by Socket on May 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core sticker-generation behavior is coherent, but the data path is not: OpenRouter calls are routed through an unverified SC-Proxy that injects credentials instead of using the official direct API flow. That creates a meaningful intermediary access risk to prompts, images, outputs, and auth, even though the rest of the capability set is proportionate to the stated purpose.
Confidence: 87%Severity: 72%
Audit Metadata