tapestry

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent, and most network/data flows match content extraction. However, it combines arbitrary external content ingestion with Bash+Write privileges, includes an unpinned auto-install path, and references an unclear third-party extractor CLI, creating meaningful supply-chain and prompt-injection risk even without clear evidence of malware or credential theft.

Confidence: 84%Severity: 63%
Audit Metadata
Analyzed At
Mar 18, 2026, 05:13 PM
Package URL
pkg:socket/skills-sh/ovachiever%2Fdroid-tings%2Ftapestry%2F@e82867ca114c9af08ad452180355b2fde72053c7