social-creative-designer

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s creative-design behavior is broadly aligned with its stated purpose, and the PyPI video-export dependency is normal. The main concern is trust and data-flow opacity around the Nano Banana MCP and ambiguous fallback API routing: the skill sends client photos and brand materials to an external service whose publisher and endpoint are not verified in the skill text. This is not confirmed malware, but it is a medium-high risk skill due to unverifiable external service provenance and remote handling of client assets.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Mar 31, 2026, 07:53 PM
Package URL
pkg:socket/skills-sh/stevenflanagan1%2Fsocial-ai-team%2Fsocial-creative-designer%2F@83cfe8c70793358218107cfb45806072bc59aab3
Security Audit — socket — social-creative-designer