anygen-image

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core function aligns with image generation, and the credential requested is proportionate, but it relies on an external CLI to handle auth and encourages transitive installation of another skill. With only partial verification of the CLI publisher/package relationship, this is not clearly malicious but carries meaningful supply-chain and trust-chain risk.

Confidence: 82%Severity: 57%
Audit Metadata
Analyzed At
Apr 6, 2026, 07:42 AM
Package URL
pkg:socket/skills-sh/anygenio%2Fanygen-skills%2Fanygen-image%2F@256f73f2bc97290ac076e8d45825c595d2a65458