scientific-slides

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill's purpose and capabilities are consistent with creating AI-generated slide images and assembling presentations, but it relies on an external image-generation service and explicitly instructs uploading local files and prior slides to that service. That design is plausible for legitimate use but creates a meaningful data-exfiltration risk if users attach sensitive or proprietary figures (or if the underlying script calls an untrusted endpoint). There is no evidence of deliberate malware or obfuscation in the provided text, but the lack of explicit data-handling, retention, or privacy safeguards and the encouragement to attach arbitrary files make this skill SUSPICIOUS from a supply-chain/data-leak perspective. Recommend: review the actual scripts (generate_slide_image.py) to confirm the exact network endpoints, TLS usage, and data retention policies; and add explicit warnings to users about what not to attach and provide an on-premise/local generation option or privacy guarantees if possible.

Confidence: 70%Severity: 45%
Audit Metadata
Analyzed At
Feb 15, 2026, 07:57 PM
Package URL
pkg:socket/skills-sh/davila7%2Fclaude-code-templates%2Fscientific-slides%2F@82e6db87ae73a95f2e683c973a80708532b355c2