social-media-carousel

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The design supports automated generation of carousel visuals via an external CLI, which is functionally appropriate but introduces non-trivial supply-chain and runtime-execution risks due to the download-and-execute installation pattern and transitive tooling. To improve safety, employ pinned, signed artifacts, verify checksums against trusted sources, avoid implicit curl|sh installs, and limit or audit transitive skill installations. If these controls cannot be established, treat as elevated risk and implement sandboxing or offline rendering with trusted components.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 12:32 PM
Package URL
pkg:socket/skills-sh/tul-sh%2Fskills%2Fsocial-media-carousel%2F@a70fd474d3e5ae9e7ecdaa30b7826ab6c7ac401d