social-media-carousel
Fail
Audited by Socket on Mar 25, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
SUSPICIOUS. The stated purpose matches image-generation behavior, but the skill relies on a pipe-to-shell external CLI installer, routes authentication through that CLI, and asks the agent to install more skills. Same-domain documentation and checksums suggest a legitimate ecosystem, yet the trust footprint is larger than a simple social media design guide and not fully verifiable from the provided evidence.
Confidence: 84%Severity: 80%
Audit Metadata