cloudrelay-imagegen

Warn

Audited by Socket on Sep 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's image-generation behavior is coherent, but its core design routes multiple providers' credentials through CloudRelay's own gateway instead of official provider APIs, and it reads raw local credential stores before making network calls. No exploit code or overt exfiltration beyond the stated gateway use is visible, but the third-party credential forwarding and secret handoff via chat make the skill medium-high risk.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Sep 10, 2026, 03:22 AM
Package URL
pkg:socket/skills-sh/cloudrelay-code%2Fcloudrelay-imagegen-skill%2Fcloudrelay-imagegen%2F@408ceb2f7c3ac068926bb6d47be736ec7e5970f7
Security Audit — socket — cloudrelay-imagegen