novelai-workflows

Warn

Audited by Socket on Jul 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent, and the network endpoints match NovelAI, but the skill relies on a non-official personal CLI/MCP implementation and forwards NovelAI credentials to it. That makes the footprint disproportionate to a simple workflow-guide skill and raises significant supply-chain and credential-handling risk.

Confidence: 86%Severity: 82%
Audit Metadata
Analyzed At
Jul 28, 2026, 04:40 PM
Package URL
pkg:socket/skills-sh/xinvxueyuan%2FNovelAI-Image-MCP%2Fnovelai-workflows%2F@4a78ce811a71739e6916f35bbc0e98025a55d1e564fd82cc5e73f1aed5a96a2a
Security Audit — socket — novelai-workflows