logo-batch-generator

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the overall purpose is coherent, and the API endpoint/model align with Gemini logo generation, but the skill’s trust model is weak because an unverifiable local script receives the raw API key and performs the network call. This is not confirmed malware, but it is a medium-high security risk due to credential forwarding and opaque execution.

Confidence: 85%Severity: 82%
Audit Metadata
Analyzed At
Apr 8, 2026, 06:31 AM
Package URL
pkg:socket/skills-sh/zephyrwang6%2Fdraw-skill%2Flogo-batch-generator%2F@f85bba66120fbbf27bb04914498cb61284dea222
Security Audit — socket — logo-batch-generator