subtoken-imagegen

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: internally coherent as a Subtoken-specific image API skill, but the core design routes prompts, images, and API credentials to a third-party intermediary domain rather than an official image API endpoint. Scope is otherwise proportionate and there is no clear evidence of malware or hidden exfiltration beyond the declared service usage.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 08:24 AM
Package URL
pkg:socket/skills-sh/CatfishW%2Fsubtoken-imagegen-skill%2Fsubtoken-imagegen%2F@9a88c13b2352be60ec20b105316a20fba0705999
Security Audit — socket — subtoken-imagegen