media-storage

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill presents a coherent pattern for media upload/storage with metadata and attachments, aligned with its described purpose. It relies on external storage backends (R2/S3), a color-extraction API, and CDN/presigned URLs, which is reasonable for the intended domain. However, there are security considerations: credential handling via environment variables without explicit least-privilege wiring, reliance on MD5 for checksums, and data flows to external services requiring explicit access control and privacy controls. The overall footprint is plausible and moderate in risk (suspicious-to-benign range), but it warrants careful credential management, explicit security controls for presigned URL lifetimes, and stronger integrity hashing to elevate safety. In its current form, it is not malicious but should be treated as a MEDIUM-RISK pattern requiring follow-up on authentication scopes, data privacy, and error handling.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 02:20 AM
Package URL
pkg:socket/skills-sh/dev-goraebap%2Fsveltekit-skills%2Fmedia-storage%2F@4d78d75c744095a45a4553794051c702bd39d6aa