snipgrapher
Warn
Audited by Socket on Mar 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is coherent for a code-to-image skill, but its core execution path relies on an unverified external CLI package invoked via unpinned `npx`. There is no evidence of credential theft or exfiltration, yet the install/execution trust is disproportionally weak because the package provenance cannot be confirmed.
Confidence: 84%Severity: 72%
Audit Metadata