image-edit
Warn
Audited by Socket on Aug 8, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's image-editing purpose matches its core behavior, and the Luxin domains/repo/CLI appear internally consistent. Risk comes from unpinned `npx` execution, explicit transitive skill installation, and routing user images/prompts/tokens through Luxin's hosted service with durable retention. This looks more like a coherent hosted SaaS skill than malware, but its install and data-flow footprint is broader than a minimal image-edit helper.
Confidence: 88%Severity: 58%
Audit Metadata