figure-to-life

Warn

Audited by Socket on Feb 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Not malware but potentially harmful/misuse-prone. The skill's conversion capabilities align with its stated purpose, but the hardcoded ethnicity mapping and strict biological fidelity are ethically problematic and disproportionate to the task. The skill lacks important safety controls: no checks for character age/minority status, no content safety or NSFW restrictions, no IP/copyright or consent guidance, and no explicit trusted image-generation endpoint. These omissions create moderate-to-high risk of misuse (e.g., generating sexualized or non-consensual realistic images, biased or discriminatory outputs, infringing copyrighted character likenesses) and privacy leakage depending on where the unspecified image-generation tool runs. Recommend adding age-safety checks, explicit content filters and policy blocks, removing or reworking the ethnicity-enforcement policy, and specifying/limiting trusted generation endpoints and logging/access controls.

Confidence: 80%Severity: 70%
Audit Metadata
Analyzed At
Feb 18, 2026, 12:34 PM
Package URL
pkg:socket/skills-sh/shinchven%2Fnano-banana-skills%2Ffigure-to-life%2F@5e827ab6e82f8679ca256432ec9d96146efd9a54