ppt-image-first-workflow

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's functionality is broadly consistent with its stated purpose and its API/data flow is mainly to official OpenAI usage, but the trust chain is weak: ara.so branding points to a separate third-party personal GitHub repo, installation is an unpinned git clone from a mutable branch, and users are told to import an external SKILL.md directly into their agent. This is better classified as a supply-chain and transitive-trust risk than confirmed malware.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
Apr 28, 2026, 06:07 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fppt-image-first-workflow%2F@5c4f95ca085727cc0af5ba990269fe43dcd2ad90