cloudrelay-imagegen
Warn
Audited by Socket on Sep 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's image-generation behavior is coherent, but its core design routes multiple providers' credentials through CloudRelay's own gateway instead of official provider APIs, and it reads raw local credential stores before making network calls. No exploit code or overt exfiltration beyond the stated gateway use is visible, but the third-party credential forwarding and secret handoff via chat make the skill medium-high risk.
Confidence: 89%Severity: 78%
Audit Metadata