posterskill-academic-posters
Warn
Audited by Socket on Mar 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s core behavior mostly matches its poster-generation purpose, and Overleaf/logo fetching are plausible for that task. However, trust is weakened by the publisher/install-source mismatch (ara.so branding vs personal GitHub repo), mixed skill packaging, and ingestion of untrusted web/PDF content while the agent can generate files and automate a browser. No direct credential theft or clearly malicious exfiltration is evident, but the provenance and content-ingestion risks make this higher than benign.
Confidence: 81%Severity: 61%
Audit Metadata