infographic
Warn
Audited by Socket on Apr 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The design and local file operations mostly match an infographic skill, but the core generation path depends on a third-party Nano Banana MCP intermediary that is not clearly official or strongly verifiable from the provided evidence. The biggest issue is credential forwarding and data flow through that unofficial MCP layer, plus direct .env credential handling by the agent.
Confidence: 84%Severity: 76%
Audit Metadata