q-presentations

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The q-presentations workflow is coherent and aligned with its described purpose: analyze content, generate prompts, produce images via an external AI API, overlay branding, and merge into deliverables (PPTX/PDF). Key risks center on external API access and multi-tool orchestration, with potential exposure of credentials if logs leak GEMINI_API_KEY and reliance on third-party tooling for merging. No evidence of malicious activity within this fragment; however, supply-chain and secret-management considerations warrant evaluation: secret handling, dependency trust, and lockfile/version pinning for external tools.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 07:48 PM
Package URL
pkg:socket/skills-sh/tyrealq%2Fq-skills%2Fq-presentations%2F@a028874bab8c2987e50bd7b98762103c8bda51a1