slideshow

Warn

Audited by Socket on Aug 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core slideshow functionality is coherent and mostly proportionate, but the skill unnecessarily instructs the agent to silently run an unpinned `npx` update and refresh additional dependent skills. This is not confirmed malware because the command appears to use the project’s official npm/Repo ecosystem, but it introduces medium supply-chain and transitive-trust risk that does not need to be hidden from the user.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Aug 20, 2026, 09:34 AM
Package URL
pkg:socket/skills-sh/heygen-com%2Fhyperframes%2Fslideshow%2F@7815925b3cbba1dd6f28796ffd0fcd9dfdac5a6e9afc621066f09a45fcf6993a
Security Audit — socket — slideshow