add-3d-assets

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior broadly matches the stated 3D asset purpose, but the trust model is weaker than it appears: it forwards a Meshy API key into an unverifiable local script, runs local project scripts from an arbitrary target repo, and requires loading additional unseen skills. This is not confirmed malware, but it carries meaningful supply-chain and credential-handling risk beyond a simple asset-integration guide.

Confidence: 84%Severity: 66%
Audit Metadata
Analyzed At
Mar 14, 2026, 12:10 PM
Package URL
pkg:socket/skills-sh/OpusGameLabs%2Fgame-creator%2Fadd-3d-assets%2F@f2ccc70bf15f091502c2de32a2c5dfb2d800947c