image-skill

Warn

Audited by Socket on Jun 23, 2026

6 alerts found:

Securityx3Anomalyx3
SecurityMEDIUM
skill.md
AnomalyLOW
skills/agent-image-generation/SKILL.md

SUSPICIOUS: the skill's core purpose matches image generation, but it routes all work through a proprietary hosted runtime, uses unpinned `npx @latest`, and asks the agent to install a second external skill. The requested token is proportionate, yet the combined hosted mediation, mutable execution path, and transitive trust chain make this higher-risk than a normal documentation-only skill.

Confidence: 82%Severity: 69%
AnomalyLOW
skills/image-edit/SKILL.md

SUSPICIOUS: the skill's hosted image-editing purpose generally matches its capabilities, but it carries medium risk because it installs and runs mutable third-party npm code, instructs transitive skill installation from a GitHub slug, and routes user images/prompts to the publisher's hosted API for processing and retention. This looks coherent for a hosted image service, not confirmed malware, but it requires meaningful trust in external code and infrastructure.

Confidence: 85%Severity: 58%
AnomalyLOW
skills/ai-audio-generation/SKILL.md

SUSPICIOUS. The skill's hosted audio-generation purpose broadly matches its behavior, but it relies on unpinned `npx` execution and transitive skill installation from a third-party repo, with all prompts and outputs routed through a proprietary hosted service. No direct credential theft or clearly malicious behavior is shown, but install trust and third-party data handling make the overall risk medium.

Confidence: 84%Severity: 58%
SecurityMEDIUM
skills/creative-media/SKILL.md
SecurityMEDIUM
skills/ai-video-generation/SKILL.md
Audit Metadata
Analyzed At
Jun 23, 2026, 01:53 AM
Package URL
pkg:socket/skills-sh/danielgwilson%2Fimage-skill-cli%2Fimage-skill%2F@e7e54194cd4e436018db1c273bc7283f94f9819c
Security Audit — socket — image-skill