baoyu-article-illustrator
Warn
Audited by Socket on Mar 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s core purpose is coherent, but it delegates execution to another skill and indirectly to external runtime tooling, creating a medium transitive trust and supply-chain risk. The visible skill text does not show credential harvesting, covert behavior, or direct exfiltration, so this is not confirmed malware.
Confidence: 82%Severity: 56%
Audit Metadata