slides

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core capability matches the stated slide-editing purpose, and there is no malicious installer or unrelated credential grab. Risk comes from weak data-flow integrity: the skill sends the API key to a user-controlled base URL, exact first-party endpoint legitimacy was not strongly verifiable, and `.env.local` is executed with `source` rather than safely parsed.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Apr 21, 2026, 04:06 PM
Package URL
pkg:socket/skills-sh/compilet-dev%2Fagent-skill-layerproof%2Fslides%2F@c36aaae14bfa4ac895a2d81e9822cb39c2d26ebb