Review recommended
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
warnThe skill includes scripts for media processing and dependency management that involve runtime installation of Node.js packages and system command execution. While these tools include safety measures like lifecycle script blocking and confirmation prompts, the use of dynamic code loading from external sources and the presence of an indirect prompt injection surface in the design picker templates warrants review.
Socket
passNo alerts
Snyk
passRisk: LOW · No issues