ni-poster

Warn

Audited by Socket on Aug 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's stated purpose matches poster generation, and there is no direct evidence of credential theft, exfiltration endpoints, or malicious payloads. However, its runtime-agnostic design delegates execution to unspecified local, MCP, or third-party image tools, including a named unofficial GitHub example, creating medium supply-chain and trust-boundary risk disproportionate to a tightly scoped skill.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Aug 22, 2026, 11:11 PM
Package URL
pkg:socket/skills-sh/ttttstc%2Fni-skill%2Fni-poster%2F@fb0d4c8c9c75e239ac731a978809ed477d54b5c9ec33f3a0a3d0638c48fab7f0
Security Audit — socket — ni-poster