gpt-image-2

Warn

Audited by Socket on Jul 22, 2026

1 alert found:

Anomaly
AnomalyLOW
skill-report.json

The most significant concerns are privacy-sensitive handling of hidden Codex session rollout files under the user’s home directory and a race-prone mechanism for selecting “new” rollout files that could inadvertently include concurrent session artifacts. No strong evidence of overt malware (e.g., credential theft, persistence, or C2 exfiltration) is apparent from the provided material; however, the design-level data-handling behavior warrants careful review, particularly around session file selection and output path/path validation.

Confidence: 45%Severity: 65%
Audit Metadata
Analyzed At
Jul 22, 2026, 07:56 AM
Package URL
pkg:socket/skills-sh/aiskillstore%2Fmarketplace%2Fgpt-image-2%2F@192561bff1a1e7cb394660d4ef6046d8118b851f1d2be9ebf97359fb8173c708
Security Audit — socket — gpt-image-2