qiaomu-info-card-designer
Warn
Audited by Socket on Apr 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core card-generation workflow is coherent, and installs appear proportionate, but the skill routes arbitrary URLs through third-party proxy services and processes untrusted remote content with file-writing/rendering capabilities. Main risk is data-flow leakage and prompt-injection exposure rather than confirmed malware.
Confidence: 87%Severity: 59%
Audit Metadata