ideogram-migration-deep-dive

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's migration capabilities broadly fit its stated purpose, and its data flows do not show obvious credential harvesting or proxy interception. However, the referenced Ideogram SDK package and documentation domain are not publicly verified as official, while the skill asks the agent to install and execute that package and grants broad file/edit/kubectl powers. This is more consistent with a high-trust but weakly verified migration guide than confirmed malware.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
Mar 24, 2026, 04:44 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fideogram-migration-deep-dive%2F@b02adc441ef8faf0b003c4ee54cfbfad2bac381d