diagram-to-image
Warn
Audited by Socket on Sep 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's purpose and actions generally align, but its core rendering flow depends on a third-party remote service with unclear ownership/provenance and sends user content off-machine. No credential harvesting or overtly malicious behavior is evident, so this is better classified as medium-risk external-service trust and data-flow exposure rather than malware.
Confidence: 85%Severity: 56%
Audit Metadata