blog-writer

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s main blog-writing behavior is proportionate and coherent, but it delegates cover generation to an unverifiable local script and likely forwards `GEMINI_API_KEY` to it. That black-box dependency is the main risk; without it, the skill would be largely benign.

Confidence: 85%Severity: 82%
Audit Metadata
Analyzed At
Mar 29, 2026, 07:15 AM
Package URL
pkg:socket/skills-sh/maroffo%2Fclaude-forge%2Fblog-writer%2F@0140aec211fd7d0615d331a7dd1f800eb02ee576