character-design-sheet
Warn
Audited by Socket on May 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s image-generation purpose is coherent, but its footprint includes transitive skill installation, mutable raw GitHub install docs, and credential use through an external CLI. This looks more like a legitimate but higher-trust workflow than malware; the main concerns are supply-chain expansion and credential forwarding rather than clear exfiltration or deception.
Confidence: 82%Severity: 64%
Audit Metadata