card

Warn

Audited by Socket on May 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core card-generation workflow is coherent, but the skill’s trust model is weakened by mandatory login, explicit token-file use, and especially autonomous install/upgrade of an external CLI whose official provenance is not established in the provided evidence. This looks more like a legitimate hosted-tool skill with notable supply-chain and credential-handling risk than confirmed malware.

Confidence: 84%Severity: 80%
Audit Metadata
Analyzed At
May 18, 2026, 06:06 AM
Package URL
pkg:socket/skills-sh/VoxFlowStudio%2Fskills%2Fcard%2F@53ec258eced4b0887f08318fa9a270a668bd1c18
Security Audit — socket — card