modly-image-to-3d
Warn
Audited by Socket on Mar 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core local image-to-3D purpose is coherent, and the documented localhost data flow is consistent with that purpose, but the extension system materially expands trust by installing and executing Python code from user-supplied GitHub repos. That makes the skill higher risk than a normal local AI app even without signs of direct credential theft or exfiltration.
Confidence: 86%Severity: 74%
Audit Metadata