gpt-image-2-gen

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
bin/cli.js

No direct malicious payload is evident in the provided fragment: it is an installer that copies bundled assets, verifies required local tools, and validates a provided API key via a fixed HTTPS endpoint. However, it meaningfully increases security risk by persisting the raw EVOLINK_API_KEY in plaintext into user shell startup files and by installing chmod+x shell scripts from the package content. Those behaviors warrant review of the packaged scripts/ directory and user-facing guidance to avoid accidental key leakage (e.g., from shared dotfiles).

Confidence: 62%Severity: 63%
Audit Metadata
Analyzed At
Apr 28, 2026, 01:41 AM
Package URL
pkg:socket/skills-sh/EvoLinkAI%2Fseedance2-video-gen-skill-for-openclaw%2Fgpt-image-2-gen%2F@c31c8ce63497a3452388b632737231a4bdb9baa1