blog-writer
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s main blog-writing behavior is proportionate and coherent, but it delegates cover generation to an unverifiable local script and likely forwards `GEMINI_API_KEY` to it. That black-box dependency is the main risk; without it, the skill would be largely benign.
Confidence: 85%Severity: 82%
Audit Metadata