place-to-contour-animator

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated purpose is coherent and scope is narrow, but its core behavior relies on unverifiable local executable scripts in user directories rather than a verifiable packaged tool or documented same-org release. No clear credential theft or malicious data routing is shown, so this is not confirmed malware, but the opaque local execution path makes it high security risk.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Mar 25, 2026, 08:58 AM
Package URL
pkg:socket/skills-sh/vibe-motion%2Fskills%2Fplace-to-contour-animator%2F@68c0486eedb070d0a8658083df18ab9cb204cf5b