og-image-design

Warn

Audited by Socket on May 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core image-generation purpose aligns with the commands and remote services, and the Belt dependency appears to follow official same-brand distribution. The main concerns are transitive skill installation, reliance on an external CLI/service for authenticated operations, mutable raw GitHub install docs, and an example that fetches untrusted search content. This looks more like a legitimate but medium-risk ecosystem-dependent skill than outright malware.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 19, 2026, 07:48 AM
Package URL
pkg:socket/skills-sh/inference-sh%2Fskills%2Fog-image-design%2F@96c590f1c42690cf3f03b7b84053080fa4a2d2c8