selfie

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The selfie skill is largely aligned with its stated purpose: private, owner-scoped selfie generation using a local album and local generation tools, with explicit boundaries against group-wide sharing. The strongest concerns are the NSFW bypass directive and the local server fallback, which could be exploited if chat-context boundaries fail or if the local environment is compromised. Overall security posture is Moderate: low likelihood of remote data leakage, but reasonable concern for local availability, abuse potential in NSFW mode, and process persistence risks. Recommended strengthening includes explicit access-control checks, clarified consent handling for NSFW prompts, and safer server lifecycle management.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 09:33 AM
Package URL
pkg:socket/skills-sh/ninehills%2Fskills%2Fselfie%2F@5b886509e013dcfa0f3493dc78d2cb2e2a85366e