youtube-thumbnail-design

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s stated purpose and capabilities mostly align: it teaches thumbnail design and uses inference.sh for image generation. The main concerns are transitive skill installation (`npx skills add ...`) and reliance on an external CLI/auth flow, which broaden trust beyond this document. Data flows appear proportionate and same-vendor, so this is not strongly malicious, but it carries medium supply-chain and trust-chain risk.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:28 PM
Package URL
pkg:socket/skills-sh/inference-sh%2Fagent-skills%2Fyoutube-thumbnail-design%2F@344dd7fa12f4fabb3c21cbcd0217f33e3f4f607e