faceswap

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The main behavior aligns with a cloud face-swap service and uses same-domain API auth, so this is not clearly malicious. However, it uploads sensitive biometric media to external storage, returns public URLs, and instructs installation of a second skill whose exact official identity was not well verified, creating moderate supply-chain and privacy risk.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 20, 2026, 01:59 AM
Package URL
pkg:socket/skills-sh/verging-ai%2Fagent-skills%2Ffaceswap%2F@ba745b8c167116983d3c45a7204a151ff6391202