auto-blog-cover

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill's stated purpose matches its described capabilities and is plausible for automating blog cover generation. There is no direct evidence in the provided text of malware or intentional sabotage (no hardcoded secrets, no inline network calls, no shell-exec patterns). However, the design delegates critical work to external skills (cover-generator and image-uploader) and instructs installing dependencies from requirements.txt without pinning or integrity checks. Those transitive dependencies and unverified installer steps create a moderate supply-chain and data-exfiltration risk: an attacker controlling the cover-generator or image-uploader, or a compromised pip package, could receive blog content and uploaded images or harvest credentials. Recommend requiring explicit, pinned dependencies, documenting the uploader endpoint and credential handling, and auditing/locking the cover-generator and image-uploader implementations before use.

Confidence: 85%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 02:21 AM
Package URL
pkg:socket/skills-sh/crossoverJie%2Fskills%2Fauto-blog-cover%2F@26ebbe8d0cf8c941901d0b359eecc81ca6205960