posterskill-academic-posters

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core behavior mostly matches its poster-generation purpose, and Overleaf/logo fetching are plausible for that task. However, trust is weakened by the publisher/install-source mismatch (ara.so branding vs personal GitHub repo), mixed skill packaging, and ingestion of untrusted web/PDF content while the agent can generate files and automate a browser. No direct credential theft or clearly malicious exfiltration is evident, but the provenance and content-ingestion risks make this higher than benign.

Confidence: 81%Severity: 61%
Audit Metadata
Analyzed At
Mar 20, 2026, 08:22 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fposterskill-academic-posters%2F@0a109ce6e647e21f12151a5e34ab8adb6ea2738c