og-image-creator

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Based on the provided skill/instruction document (no implementation code included), the described capabilities (reading the repo, extracting logos/styles, rendering with Playwright, saving OG images, updating metadata) align with its stated purpose and are proportionate. There are normal network flows for Playwright browser downloads and optional use of OG preview services. No hardcoded credentials, obfuscated code, or suspicious external endpoints are present in this document. However, the actual scripts referenced were not provided for review; those scripts could contain malicious behavior or unsafe file-modifying logic. Recommend reviewing the contents of scripts/analyze_codebase.py and scripts/generate_og_images.py before running, and ensure any automatic edits to source files are explicit, backed up, and permissioned.

Confidence: 80%Severity: 15%
Audit Metadata
Analyzed At
Feb 16, 2026, 02:40 AM
Package URL
pkg:socket/skills-sh/chongdashu%2Fcc-skills%2Fog-image-creator%2F@6034e153ac3de0698a76be218b23ffac7845b94c