content-illustrator

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is coherent with its stated purpose: it analyzes article content, selects among 14 illustration styles, generates images through an internal API, and embeds references back into the article. The only notable security considerations are standard credential handling for the API key (DOUBAO_API_KEY) and dependency on the internal image-generation API. There is no evident data leakage, unauthenticated remote exfiltration, or arbitrary download-execute behavior. Overall, the footprint is proportionate to its purpose, with moderate governance over credentials and dependencies. Recommend ensuring secure handling of DOUBAO_API_KEY, explicit permission prompts for per-illustration actions if used in a broader automation, and maintain TLS verification for API calls.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 06:55 AM
Package URL
pkg:socket/skills-sh/hhhh124hhhh%2FSkillMate%2Fcontent-illustrator%2F@4b217d73b770860f8ec7315ff7b3876fd2b7afd3