imagegen

Warn

Audited by Socket on Aug 7, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
skills/imagegen/SKILL.md

The core image-generation purpose is coherent, but the fallback path is security-sensitive: it reads a local API key file and sends credentials and prompts to an arbitrary auth.json-defined endpoint, potentially a third-party proxy. The skill is better classified as suspicious/high-risk for data-flow and credential-forwarding reasons, not confirmed malware.

Confidence: 86%Severity: 68%
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent for image generation, and there is no malware-grade installer or pre-execution payload. However, the fallback path reads a raw API key from disk and forwards it to an arbitrary endpoint/proxy, which weakens data-flow integrity and creates meaningful credential-forwarding risk disproportionate to a normal official-API integration.

Confidence: 88%Severity: 71%
Audit Metadata
Analyzed At
Aug 7, 2026, 07:52 AM
Package URL
pkg:socket/skills-sh/afu-it%2Fcreate-image-codex%2Fimagegen%2F@a3e736580a68fd2fce5bfd649527be474576e370
Security Audit — socket — imagegen