gis

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This document is a benign integration/reference skill for GIS tasks (CRS info, format handlers, and instructions to export project files and scripts for QGIS and Blender). It does not contain remote download-execute patterns, credential harvesting, obfuscated payloads, or network exfiltration. The main risks are normal supply-chain and operational concerns: reliance on optional third-party GIS libraries (rasterio, geopandas/fiona) which should be installed from trusted registries and pinned, and the fact that generated Python scripts will run with the privileges of the user when opened in Blender/QGIS — users should only execute exporter-generated scripts from trusted sources. Overall there is low likelihood of malicious intent based on the provided content.

Confidence: 85%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 02:33 PM
Package URL
pkg:socket/skills-sh/vamseeachanta%2Fworkspace-hub%2Fgis%2F@6cdd4c6babf8e0823495a0e7498643c710f08016