upscale-image

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
.clawnet/unsigned-skill.json

The package fragment demonstrates a concerning pattern: a large, hex-encoded payload that contains cloud- provisioning instructions and endpoints, paired with provenance data. While not showing direct executable code, the content could influence runtime behavior via a loader that decodes and executes or guides actions based on the payload. This constitutes a non-trivial supply-chain risk and warrants strict validation of decoding, signature verification, and any runtime handling of opReturnHex to prevent credential leakage or unintended cloud resource provisioning.

Confidence: 56%Severity: 65%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:31 PM
Package URL
pkg:socket/skills-sh/b-open-io%2Fgemskills%2Fupscale-image%2F@5dbffcaf55a3c3737a3e74cf329dbfa9ea94c612