line-sticker-creator

Warn

Audited by Socket on Mar 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Overall, the skill's footprint is broadly coherent with its stated purpose of generating LINE sticker packs via an image-generation workflow, including validation and packaging steps. The main security considerations center on trust in the image-creator plugin and external providers: verification of plugin provenance, secure handling of API keys, and explicit data-flow controls for credentials when communicating with external services. There is no explicit malicious behavior observed, but the reliance on local plugins and multiple external providers warrants caution (SUSPICIOUS rather than benign). The workflow would benefit from clearly documented provenance checks, explicit credential management policies, and concrete network data-flow diagrams to ensure data is only sent to approved, known endpoints with proper encryption.

Confidence: 62%Severity: 55%
Audit Metadata
Analyzed At
Mar 12, 2026, 03:42 AM
Package URL
pkg:socket/skills-sh/haboshi%2Fclaude-code-skills%2Fline-sticker-creator%2F@5620892101d36f5fa59c665f529e245c3fef377b