og-image-design

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill aims to provide OG image design via a remote CLI, which relies on downloading and executing an unverifiable binary from an external source. This introduces legitimate supply-chain risk and potential remote code execution risk, despite checksum verification being mentioned. The data flow involves user-provided content being processed by an external binary, which is a plausible risk area if the binary is compromised or if the agent automates execution without explicit user consent for each run. Overall, the footprint is coherent with its stated purpose but presents notable security concerns around binary provenance and execution autonomy.

Confidence: 65%Severity: 75%
Audit Metadata
Analyzed At
Mar 8, 2026, 02:51 AM
Package URL
pkg:socket/skills-sh/1nfsh-s3%2Fskills%2Fog-image-design%2F@5e5dc7fcf5243e37f5ed7226ca1a7448da0c8a94