image-edit

Warn

Audited by Socket on Aug 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's image-editing purpose matches its core behavior, and the Luxin domains/repo/CLI appear internally consistent. Risk comes from unpinned `npx` execution, explicit transitive skill installation, and routing user images/prompts/tokens through Luxin's hosted service with durable retention. This looks more like a coherent hosted SaaS skill than malware, but its install and data-flow footprint is broader than a minimal image-edit helper.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Aug 8, 2026, 11:25 PM
Package URL
pkg:socket/skills-sh/danielgwilson%2Fluxin%2Fimage-edit%2F@ff3cfdc7e26611f9f029837bb75dab1d5bedc02dc8d7df51b5b715e15c69f7fb
Security Audit — socket — image-edit