Sketch

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Overall, the skill footprint is coherent with its stated purpose: it focuses on generating Python code to interact with the Gemini API and provides sufficient guidance and structure without performing network calls or handling credentials beyond the environment-provided API key. The risk profile is low to moderate (benign to suspicious in edge-cases) because it relies on standard, well-known technologies and avoids executing external binaries or exfiltrating data itself. No credential harvesting, download/execute chains, or autonomous real-world actions are present in the analyzed artifact.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 06:29 PM
Package URL
pkg:socket/skills-sh/simota%2Fagent-skills%2Fsketch%2F@507bd8ccc6275a08b75548fbffb7a881fc941ec0