subtoken-imagegen
Warn
Audited by Socket on May 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: internally coherent as a Subtoken-specific image API skill, but the core design routes prompts, images, and API credentials to a third-party intermediary domain rather than an official image API endpoint. Scope is otherwise proportionate and there is no clear evidence of malware or hidden exfiltration beyond the declared service usage.
Confidence: 100%Severity: 60%
Audit Metadata