modly-image-to-3d

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core local image-to-3D purpose is coherent, and the documented localhost data flow is consistent with that purpose, but the extension system materially expands trust by installing and executing Python code from user-supplied GitHub repos. That makes the skill higher risk than a normal local AI app even without signs of direct credential theft or exfiltration.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Mar 21, 2026, 04:39 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fmodly-image-to-3d%2F@6fd1634b422f9be52bafe3dfba43291f0882f0bd