performing-steganography-detection
Warn
Audited by Socket on Mar 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is broadly coherent with its stated digital-forensics purpose and keeps data local, but it grants an AI agent offensive-capable security analysis/extraction workflows. Install trust is mostly acceptable via standard package managers, though one installer path (`pip install zsteg`) is inconsistent with upstream documentation and the installs are unpinned. Overall this is not malicious or credential-harvesting, but it is a high-risk cybersecurity skill for agent use.
Confidence: 90%Severity: 74%
Audit Metadata