generate-image
Warn
Audited by Socket on Jul 7, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core capability matches the stated purpose, and official Gemini/OpenAI usage looks coherent. The main risk is intentional support for arbitrary OpenAI-compatible base URLs, which can route prompts, images, and API keys through unrelated third-party gateways like api.tu-zi.com; combined with runtime dependency resolution via uv, this makes the skill medium risk rather than benign.
Confidence: 88%Severity: 61%
Audit Metadata