photo-editor

Warn

Audited by Socket on Aug 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core image-generation purpose is plausible, but the skill requires a gateway credential and routes all prompts/images through a third-party intermediary instead of a direct provider API. Same-org documentation reduces the chance of outright malware, yet credential forwarding, transitive CLI trust, and proxy-style data flow make the skill medium-to-high risk for a developer agent.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Aug 24, 2026, 01:56 PM
Package URL
pkg:socket/skills-sh/ai-hub-admin%2Fcraftsman-agent%2Fphoto-editor%2F@498cfc93cb20c7f26ece4046c3adf7daf9c8f9440786aae7476c2851602da030
Security Audit — socket — photo-editor