recreate-thumbnails

Fail

Audited by Socket on Mar 6, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The code/package description implements a face-swapping thumbnail generator that necessarily uploads sensitive images and prompts to a third-party image model. There is low evidence of embedded malware or obfuscation in the provided fragment, but the tool poses a significant ethical and privacy risk because it facilitates realistic deepfakes and transfers personally identifiable images to an external service without documented consent or mitigations. Recommended actions before using or publishing: require documented consent from subjects, add explicit watermarking or provenance metadata to outputs, implement optional local-only operation or support for self-hosted models, restrict and rotate API credentials, and review the third-party provider's retention and privacy policies. Treat the package as high misuse risk even if it lacks direct malware indicators.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 6, 2026, 02:20 PM
Package URL
pkg:socket/skills-sh/aiagentwithdhruv%2Fskills%2Frecreate-thumbnails%2F@7580315069beea6c4362c0e4c1f67eafb552922b